TTO-2026-0826-001 · August 26, 2026 Nation-StateLaw Enforcement

FBI and DOJ Seize QScan and QTRouter Hacking Platforms Used by Chinese State Hackers Against NASA, Federal Reserve, and US Senate

justice.govQTFY QT QTCYBERNanjing Xinjiuwei Network TechnologyQScan QTRouterNASA Federal Reserve DOJ NIH SenateCourt-authorized domain seizuresFourth PRC disruption since 2023Ministry of State Security PLA customers

Summary

The United States Department of Justice and FBI announced on August 26, 2026 the court-authorized seizure of infrastructure associated with two complementary hacking platforms, QScan and QTRouter, operated by a threat actor designated QTFY, also known as QT and QTCYBER, which provided reconnaissance, proxy management, and operational routing capabilities to Chinese state-sponsored hackers as a technical quartermaster service. According to court documents, QTFY is employed by the Nanjing Xinjiuwei Network Technology Company and sold hacking services to customers including China's Ministry of State Security and the People's Liberation Army. QScan automatically scans and infects internet-of-things devices worldwide, enrolling them in the QTRouter network. QTRouter consists of those compromised IoT devices combined with commercial proxy service devices and leased virtual private servers, providing a layered routing infrastructure that conceals the true origin of attacks. Among QTFY's documented targets are NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the United States Senate. The court-authorized seizures targeted domains hard-coded into the QScan and QTRouter malware, rendering both platforms inoperable. FBI Director Kash Patel described the operation as part of a broader strategy to dismantle PRC-linked cyber threats. The DOJ noted that today's action is the fourth in a series of court-authorized technical operations against PRC-linked hacking infrastructure, following the removal of PlugX malware from more than 4,000 US computers in 2025, the disruption of the Flax Typhoon botnet in 2024, and the disruption of a Volt Typhoon botnet in 2023.

Timeline

DateEvent
2023FBI disrupts Volt Typhoon botnet used to conceal exploitation of US and foreign critical infrastructure
2024FBI disables Flax Typhoon botnet of hundreds of thousands of infected IoT devices
2025FBI removes PlugX malware from 4,000+ US computers infected by Mustang Panda
Aug 26, 2026DOJ and FBI announce court-authorized seizure of QScan and QTRouter domains — both platforms rendered inoperable
Aug 26, 2026QTFY confirmed employed by Nanjing Xinjiuwei Network Technology Company — served MSS and PLA customers
Aug 26, 2026Confirmed targets: NASA, Federal Reserve, Departments of Energy, Justice, and HHS, NIH, US Senate

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
justice.gov93.0Live
WarmBadge Intelligence Snapshot · Captured: August 26, 2026 UTC

Context

justice.gov scores 93.0 — one of the highest scores in The Trust Observatory's domain intelligence database, consistent with a federal law enforcement domain that has maintained institutional trust infrastructure across decades. The QTFY disruption is significant in context: it is the fourth consecutive year the DOJ and FBI have announced a court-authorized technical operation against PRC-linked cyber infrastructure. Volt Typhoon in 2023, Flax Typhoon in 2024, Mustang Panda in 2025, QTFY in 2026. The pattern reflects sustained, large-scale Chinese cyber operations against US critical infrastructure and a sustained US government response. The quartermaster model that QTFY represents — selling hacking-as-a-service to state intelligence and military customers — is a structural feature of China's cyber ecosystem, not an isolated contractor relationship. Disrupting one quartermaster's infrastructure does not eliminate the underlying demand.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 26, 2026