Security4 distinct publishers3 min readPublished
Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The division of labour between the two seized products is the part worth reading twice. QScan handled acquisition, scanning the internet and automatically infecting IoT devices, according to the Justice Department [5]. QTRouter handled use: an obfuscation network that made activity appear to come from any of those infected devices [6]. A home router in a third country therefore shows up twice in the same operation, once as a victim and once as the apparent origin of an intrusion against someone it has never heard of [1].
FBI Assistant Director Brett Leatherman described the scanning platform as scouring the internet for vulnerable smart devices such as home routers and security cameras, infecting thousands of them and feeding them into a botnet [8], and said the group exploited devices in more than 130 countries [7]. The named victims, by contrast, are American: the Federal Reserve, the Department of Energy, the DOJ itself, the Senate and NASA, plus HHS, NIH, hospitals, telecommunications providers, power companies, financial institutions and defence contractors [4]. The two populations barely overlap [2]. Most owners of the exploited devices were never targets. They were plant.
The DOJ says the tools let operators make attacks look as though they came from other countries, and in some cases as though the incidents were caused by local attackers [9]. For anyone who has triaged an incident since 2018 [1], that second outcome is the expensive one. A misread of nationality is bad; a misread that says "this came from inside our own market" routes the case to the wrong team, the wrong legal theory and the wrong disclosure obligations.
Against that, the earliest case in the affidavit does not fit the pattern. In the 2019 NASA incident, one of the first the FBI investigated, attackers tried to exploit a Pulse Secure VPN flaw and investigators traced the IP addresses back to locations and email addresses in China [11]. So the laundering was not applied everywhere, or it leaked. Attribution held in that instance, which is a caution in both directions: a relay service existing does not mean every operation ran through it.
The FBI also says the group operated inside a network of hackers-for-hire and government clients in China [10] and had unspecified customers outside the Chinese government [12]. Relay infrastructure with unnamed tenants means an infected device may have carried traffic for parties the affidavit does not identify.
The takedown itself was cheap because the design was brittle: the seized domains were hard-coded into both platforms for essential tasks including communication and authentication, which rendered them inoperable [13]. The account describes no court-authorised removal of implants from devices this time, though the FBI has done exactly that before, pulling PlugX off thousands of US computers last year and disrupting the Volt Typhoon and Flax Typhoon botnets in 2024 [14][15]. Domains die; implants stay where they are. The DOJ also did not respond to questions, and the affidavit does not say which senators or committees were hit [16].
Ranked by verification strength, evidence, and original report placement.
The Department of Justice said Chinese government hackers used tools known as QScan and QTRouter to breach multiple federal agencies since 2018, announcing the takedown of the platforms on Wednesday.
The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China's Ministry of State Security and the People's Liberation Army, according to a DOJ affidavit.
The tools were used by a state-sponsored group known as QTFY that targeted US critical infrastructure and other sensitive networks, the Justice Department said.
Leatherman said Nanjing Xinjiuwei sells stolen data and hacking services to Chinese military and intelligence agencies, and that its services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them and feeds them into a botnet controlled by the adversary.
Targeted agencies included the Federal Reserve, the Department of Energy, the DOJ itself, the US Senate and NASA; other victims listed in the affidavit include the Department of Health and Human Services, the National Institutes of Health and multiple hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
QScan was used to scan and automatically infect internet of things devices around the world, the DOJ said.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Court affidavit plus independent vendor tracking
The factual core rests on an unsealed affidavit and DOJ press release corroborated in near-identical terms by four publishers, and is reinforced by named officials, a joint FBI/NSA/CNMF advisory with indicators, specific seized domains and CVEs, and independent Lumen Black Lotus Labs tracking that predates the announcement by over 18 months. It is capped below high confidence because nearly all substance is one government evidentiary filing, allegations are untested with no announced defendants, and reports conflict on when the investigation began.
Large real-world footprint, concrete disruption artefacts
This measures how far the described activity and the response actually reached in the world. Officials document devices exploited in more than 130 countries, over two million scanning and exploit tasks in a single day in 2024, 200-plus bundled proof-of-concept exploits, confirmed intrusions at multiple federal agencies and DOE national laboratories, three seized domains and a published indicator advisory. It is not higher because the number of compromised devices, the size of the relay pool and the durability of the disruption are all unquantified.
Disruption framing slightly outruns durability
Modestly overstated. The verifiable facts are strong, but the strongest headline claim, that the platforms are inoperable, comes from the agencies that performed the seizure, rests on hard-coded domains that can be re-registered elsewhere, and arrives with no arrests or indictments. Only Security Affairs qualifies it with 'at least until they rebuild it', while other coverage largely reproduces the press-release framing. Government statements about going on the offensive and stopping and prosecuting hackers are not matched by any charged defendant in the supplied material.
Enforcement announcement amplified via vendor partner
The information flow is announcement-driven and the announcers benefit from it. DOJ and FBI leadership issued promotional statements alongside the seizure, and the corroborating technical narrative comes substantially from Lumen Black Lotus Labs, a commercial security vendor that assisted the operation and published its own report on the same day. Coverage across the cluster closely tracks the press release and affidavit, with limited independent verification and no adversarial or defence-side voice.
High on facts, moderate on effect
Confidence in the core facts is high given four consistent accounts, a named front company, specified domains, CVEs and an indicator advisory. It is held below the top band by dependence on a single evidentiary filing, a documented conflict over the investigation timeline, absent quantification of compromised devices, and the untestable question of how long the disruption holds.
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 26, 2026
1 article · August 26, 2026
1 article · August 26, 2026
1 article · August 26, 2026