SecurityReports disagree7 publishers3 min readPublished Updated
DOJ seizes QScan and QTRouter: somebody else's camera was the return address
Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.
The Watch · Security desk
What happened
- Justice announced on Wednesday that it had seized QScan and QTRouter, platforms it says Chinese government hackers used to breach federal agencies since 2018.
- The affidavit names China-based Nanjing Xinjiuwei Network Technology Company as the operator, with the Ministry of State Security and the PLA as primary users.
- Both platforms were rendered inoperable because the seized domains were hard-coded into them for communication and authentication.
Why it matters
- constraint Any triage that leaned on source geography, including cases closed as local actors, was working against a service built to produce exactly that conclusion.
- exposure Owners of unmanaged cameras and routers in scores of countries carried liability for intrusions against organisations they have no relationship with.
- cost Killing the domains does not clean the devices, so remediation lands on individual owners rather than on the agencies that ran the takedown.
- contradiction The earliest case cited was traced straight back to Chinese IPs and email addresses, which argues the origin laundering was inconsistent rather than total.
The division of labour between the two seized products is the part worth reading twice. QScan handled acquisition, scanning the internet and automatically infecting IoT devices, according to the Justice Department [5]. QTRouter handled use: an obfuscation network that made activity appear to come from any of those infected devices [6]. A home router in a third country therefore shows up twice in the same operation, once as a victim and once as the apparent origin of an intrusion against someone it has never heard of [17].
FBI Assistant Director Brett Leatherman described the scanning platform as scouring the internet for vulnerable smart devices such as home routers and security cameras, infecting thousands of them and feeding them into a botnet [7], and said the group exploited devices in more than 130 countries [16]. The named victims, by contrast, are American: the Federal Reserve, the Department of Energy, the DOJ itself, the Senate and NASA, plus HHS, NIH, hospitals, telecommunications providers, power companies, financial institutions and defence contractors [4]. The two populations barely overlap [19]. Most owners of the exploited devices were never targets. They were plant.
The DOJ says the tools let operators make attacks look as though they came from other countries, and in some cases as though the incidents were caused by local attackers [9]. For anyone who has triaged an incident since 2018 [1], that second outcome is the expensive one. A misread of nationality is bad; a misread that says "this came from inside our own market" routes the case to the wrong team, the wrong legal theory and the wrong disclosure obligations.
Against that, the earliest case in the affidavit does not fit the pattern. In the 2019 NASA incident, one of the first the FBI investigated, attackers tried to exploit a Pulse Secure VPN flaw and investigators traced the IP addresses back to locations and email addresses in China [15]. So the laundering was not applied everywhere, or it leaked. Attribution held in that instance, which is a caution in both directions: a relay service existing does not mean every operation ran through it.
The FBI also says the group operated inside a network of hackers-for-hire and government clients in China [10] and had unspecified customers outside the Chinese government [11]. Relay infrastructure with unnamed tenants means an infected device may have carried traffic for parties the affidavit does not identify.
The takedown itself was cheap because the design was brittle: the seized domains were hard-coded into both platforms for essential tasks including communication and authentication, which rendered them inoperable [8]. The account describes no court-authorised removal of implants from devices this time, though the FBI has done exactly that before, pulling PlugX off thousands of US computers last year and disrupting the Volt Typhoon and Flax Typhoon botnets in 2024 [12][18]. Domains die; implants stay where they are. The DOJ also did not respond to questions, and the affidavit does not say which senators or committees were hit [13].
What to watch
- Whether the DOJ or FBI publishes device makes, models or indicators that would let owners outside the United States identify infected units.
- Whether a follow-up court order authorises removing implants from devices, as happened with PlugX, or the domain seizure is the end of the operation.
- Whether the affidavit's unnamed non-government customers of QTFY are identified, which would widen the set of parties whose traffic transited those devices.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence64
Perspective Coverage
7 publishers- Builder
- Builder 32%
- Operator
- Operator 54%
- Investor
- Investor 14%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Department of Justice said Chinese government hackers used tools known as QScan and QTRouter to breach multiple federal agencies since 2018, announcing the takedown of the platforms on Wednesday.
ReportedSupportedSource: US Department of Justice, via The Record4 sources— create a free account to open themView cited source - [2]
The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China's Ministry of State Security and the People's Liberation Army, according to a DOJ affidavit.
- [3]
The tools were used by a state-sponsored group known as QTFY that targeted US critical infrastructure and other sensitive networks, the Justice Department said.
- [4]
Targeted agencies included the Federal Reserve, the Department of Energy, the DOJ itself, the US Senate and NASA; other victims listed in the affidavit include the Department of Health and Human Services, the National Institutes of Health and multiple hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
- [5]
QScan was used to scan and automatically infect internet of things devices around the world, the DOJ said.
- [6]
QTRouter served as an obfuscation network that allowed malicious actors to conceal the origin of their attacks by making it appear that actions came from any of the infected devices.
- [7]
Leatherman said Nanjing Xinjiuwei sells stolen data and hacking services to Chinese military and intelligence agencies, and that its services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them and feeds them into a botnet controlled by the adversary.
ReportedSupportedSource: FBI Assistant Director Brett Leatherman4 sources— create a free account to open themView cited source - [8]
The FBI and DOJ said the takedown made both QScan and QTRouter inoperable because the seized domains were hard-coded into both platforms and used for essential tasks like communication and authentication.
- [9]
The tools allegedly enabled Chinese actors to make it look like the cyberattacks were coming from other countries and in some cases made it seem like the incidents were caused by local attackers.
- [10]
Leatherman said QTFY operates within a complex network of hackers-for-hire and government clients in China.
ReportedSupportedSource: FBI Assistant Director Brett Leatherman4 sources— create a free account to open themView cited source - [11]
The FBI said QTFY also had unspecified customers outside of the Chinese government.
- [12]
US law enforcement has previously obtained court orders allowing agents to enter devices and remove malware installed by hackers from China and Russia, including the FBI's removal of PlugX surveillance malware from thousands of US computers last year.
- [13]
The affidavit does not explain whether specific senators or committees were attacked, and the DOJ did not respond to requests for comment.
- [14]
Investigators said they had been investigating QTFY's infrastructure since 2018 and continued until an attack on the US Senate, which occurred this year.
- [15]
One of the first attacks the FBI investigated was a 2019 incident at NASA in which hackers attempted to exploit a vulnerability in Pulse Secure VPN; investigators traced the IP addresses used back to locations and email addresses in China.
- [16]
FBI Assistant Director Brett Leatherman said QTFY exploited devices in more than 130 countries.
- [17]
Because QScan's infected devices are the same devices QTRouter presents as the apparent source of activity, a single compromised router or camera functions both as a victim and as the origin address seen by an unrelated target.
- [18]
The FBI disrupted multiple botnets in 2024 run by Chinese government hacking operations known as Volt Typhoon and Flax Typhoon.
- [19]
The device footprint (more than 130 countries) and the named victim list (US federal agencies, hospitals, utilities, telecoms, banks and defence contractors) are largely disjoint populations, so most owners of exploited devices were relay infrastructure rather than targets.
Sources
7 independent publishers whose own reporting we read for this story.
- cyberscoop.comOfficials disrupt Chinese espionage operation that hit multiple federal agencies
2 articles · August 26, 2026
- helpnetsecurity.comFBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
2 articles · August 27, 2026
- scworld.comFBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
2 articles · August 27, 2026
- securityaffairs.comFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
1 article · August 26, 2026
- securityweek.comUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
1 article · August 27, 2026
- thehackernews.comFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
1 article · August 26, 2026
- therecord.mediaUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- China state cyber espionageFollow
- IoT SecurityFollow
- Law-enforcement cyber disruptionFollow
- Operational relay networksFollow
Entities
- QTRouterFollow
- People's Liberation ArmyFollow
- Volt TyphoonFollow
- PlugXFollow
- Kash PatelFollow
- Black Lotus LabsFollow
- U.S. Department of JusticeFollow
- QTFYFollow
- Nanjing Xinjiuwei Network Technology CompanyFollow
- Federal Bureau of InvestigationFollow
- Flax TyphoonFollow
- Ministry of State Security (PRC)Follow
- Brett LeathermanFollow
- QScanFollow
- Todd BlancheFollow