Skip to content

SecurityReports disagree7 publishers3 min readPublished Updated

DOJ seizes QScan and QTRouter: somebody else's camera was the return address

Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying DOJ seizes QScan and QTRouter: somebody else's camera was the return address
Photo: fbi.gov

What happened

  • Justice announced on Wednesday that it had seized QScan and QTRouter, platforms it says Chinese government hackers used to breach federal agencies since 2018.
  • The affidavit names China-based Nanjing Xinjiuwei Network Technology Company as the operator, with the Ministry of State Security and the PLA as primary users.
  • Both platforms were rendered inoperable because the seized domains were hard-coded into them for communication and authentication.

Why it matters

  • constraint Any triage that leaned on source geography, including cases closed as local actors, was working against a service built to produce exactly that conclusion.
  • exposure Owners of unmanaged cameras and routers in scores of countries carried liability for intrusions against organisations they have no relationship with.
  • cost Killing the domains does not clean the devices, so remediation lands on individual owners rather than on the agencies that ran the takedown.
  • contradiction The earliest case cited was traced straight back to Chinese IPs and email addresses, which argues the origin laundering was inconsistent rather than total.

The division of labour between the two seized products is the part worth reading twice. QScan handled acquisition, scanning the internet and automatically infecting IoT devices, according to the Justice Department [5]. QTRouter handled use: an obfuscation network that made activity appear to come from any of those infected devices [6]. A home router in a third country therefore shows up twice in the same operation, once as a victim and once as the apparent origin of an intrusion against someone it has never heard of [17].

FBI Assistant Director Brett Leatherman described the scanning platform as scouring the internet for vulnerable smart devices such as home routers and security cameras, infecting thousands of them and feeding them into a botnet [7], and said the group exploited devices in more than 130 countries [16]. The named victims, by contrast, are American: the Federal Reserve, the Department of Energy, the DOJ itself, the Senate and NASA, plus HHS, NIH, hospitals, telecommunications providers, power companies, financial institutions and defence contractors [4]. The two populations barely overlap [19]. Most owners of the exploited devices were never targets. They were plant.

The DOJ says the tools let operators make attacks look as though they came from other countries, and in some cases as though the incidents were caused by local attackers [9]. For anyone who has triaged an incident since 2018 [1], that second outcome is the expensive one. A misread of nationality is bad; a misread that says "this came from inside our own market" routes the case to the wrong team, the wrong legal theory and the wrong disclosure obligations.

Against that, the earliest case in the affidavit does not fit the pattern. In the 2019 NASA incident, one of the first the FBI investigated, attackers tried to exploit a Pulse Secure VPN flaw and investigators traced the IP addresses back to locations and email addresses in China [15]. So the laundering was not applied everywhere, or it leaked. Attribution held in that instance, which is a caution in both directions: a relay service existing does not mean every operation ran through it.

The FBI also says the group operated inside a network of hackers-for-hire and government clients in China [10] and had unspecified customers outside the Chinese government [11]. Relay infrastructure with unnamed tenants means an infected device may have carried traffic for parties the affidavit does not identify.

The takedown itself was cheap because the design was brittle: the seized domains were hard-coded into both platforms for essential tasks including communication and authentication, which rendered them inoperable [8]. The account describes no court-authorised removal of implants from devices this time, though the FBI has done exactly that before, pulling PlugX off thousands of US computers last year and disrupting the Volt Typhoon and Flax Typhoon botnets in 2024 [12][18]. Domains die; implants stay where they are. The DOJ also did not respond to questions, and the affidavit does not say which senators or committees were hit [13].

What to watch

  • Whether the DOJ or FBI publishes device makes, models or indicators that would let owners outside the United States identify infected units.
  • Whether a follow-up court order authorises removing implants from devices, as happened with PlugX, or the domain seizure is the end of the operation.
  • Whether the affidavit's unnamed non-government customers of QTFY are identified, which would widen the set of parties whose traffic transited those devices.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence66
Adoption
Insufficient
Hype gap+18
Incentives58
Confidence64

Perspective Coverage

7 publishers
Builder
Builder 32%
Operator
Operator 54%
Investor
Investor 14%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The Department of Justice said Chinese government hackers used tools known as QScan and QTRouter to breach multiple federal agencies since 2018, announcing the takedown of the platforms on Wednesday.

    ReportedSupportedSource: US Department of Justice, via The Record4 sources— create a free account to open themView cited source
  2. [2]

    The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China's Ministry of State Security and the People's Liberation Army, according to a DOJ affidavit.

  3. [3]

    The tools were used by a state-sponsored group known as QTFY that targeted US critical infrastructure and other sensitive networks, the Justice Department said.

Sources

7 independent publishers whose own reporting we read for this story.

  1. cyberscoop.com

    2 articles · August 26, 2026

    Officials disrupt Chinese espionage operation that hit multiple federal agencies
  2. helpnetsecurity.com

    2 articles · August 27, 2026

    FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
  3. scworld.com

    2 articles · August 27, 2026

    FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
  4. securityaffairs.com

    1 article · August 26, 2026

    FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
  5. securityweek.com

    1 article · August 27, 2026

    US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
  6. thehackernews.com

    1 article · August 26, 2026

    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
  7. therecord.media

    1 article · August 26, 2026

    US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories