Skip to content
The Next Coverage

Insurance Insights, Guides & Coverage Tips

The Next Coverage

Insurance Insights, Guides & Coverage Tips

  • Home
  • News
  • Political
  • Health
  • Entertainment
  • Home
  • News
  • Political
  • Health
  • Entertainment
Close

Search

  • Home
  • News
  • Political
  • Health
  • Entertainment
The Next Coverage

Insurance Insights, Guides & Coverage Tips

The Next Coverage

Insurance Insights, Guides & Coverage Tips

  • Home
  • News
  • Political
  • Health
  • Entertainment
  • Home
  • News
  • Political
  • Health
  • Entertainment
Close

Search

  • Home
  • News
  • Political
  • Health
  • Entertainment
Political

US Seizes China-Linked Hacking Platforms Used to Target Critical Infrastructure

By Laure Parker
August 26, 2026 4 Min Read
us seizes china linked hacking platforms qscan qtrouter

The U.S. Justice Department and FBI have seized two hacking platforms allegedly operated by a China-linked state-sponsored cyber group that targeted critical infrastructure and sensitive networks in the United States and around the world.

The court-authorized action announced Wednesday disrupted access to QScan and QTRouter, two platforms that federal investigators say were created and operated by a China-based hacking group known as QTFY.

According to court documents unsealed in the Southern District of California, QTFY is associated with Nanjing Xinjiuwei Network Technology Company, a China-based technology company. U.S. authorities allege that the group provided hacking services to paying customers, including China’s Ministry of State Security and People’s Liberation Army.

FBI and DOJ Seize QScan and QTRouter

The Justice Department said the seized domains were essential to the operation of QScan and QTRouter.

Because the domains were hard-coded into the malware and used for communication and authentication, taking control of them made the two platforms inoperable, according to federal authorities.

The operation is part of a broader U.S. effort to disrupt cyber infrastructure allegedly used by China-sponsored hackers rather than simply responding after individual attacks occur.

Attorney General Todd Blanche said the latest action was intended to stop state-sponsored hackers from targeting America’s critical infrastructure.

FBI Director Kash Patel described QScan and QTRouter as tools used by Chinese state-sponsored cyber actors to conceal the origin of their attacks.

What Are QScan and QTRouter?

QScan and QTRouter allegedly worked together as part of a broader hacking infrastructure.

According to court documents, QScan was designed to scan internet-connected devices and automatically infect vulnerable Internet of Things, or IoT, devices.

Those compromised devices could then become part of a network controlled by QTFY.

QTRouter, meanwhile, allegedly used compromised IoT devices, commercial proxy services and leased virtual private servers to create what investigators described as an “obfuscation network.”

The purpose was to make malicious communications appear to come from computers outside China.

That technique could make it more difficult for investigators and targeted organizations to determine where an intrusion originated.

US Agencies Among the Alleged Victims

The Justice Department said QTFY’s alleged intrusion activity affected organizations and government agencies in the United States.

The identified victims include:

  • National Aeronautics and Space Administration
  • Federal Reserve
  • Department of Energy
  • Department of Justice
  • Department of Health and Human Services
  • National Institutes of Health
  • U.S. Senate

The range of alleged targets makes the case particularly significant because several are directly connected to U.S. government operations, national security or critical infrastructure.

Federal authorities said QTFY’s malicious activity dates back to at least 2018.

Why IoT Devices Matter in Cyberattacks

Internet-connected devices can become useful tools for attackers when they are compromised and incorporated into larger networks.

Routers, cameras and other connected devices can provide attackers with additional infrastructure from which to send malicious traffic.

In the QScan and QTRouter operation, investigators allege that compromised devices were used not only as targets but also as part of the infrastructure supporting subsequent cyber activity.

That makes such networks difficult to trace because the traffic can appear to originate from devices located in countries or networks unrelated to the actual attacker.

Part of a Larger US Effort Against China-Linked Cyber Operations

The DOJ and FBI said Wednesday’s seizure follows several previous court-authorized operations targeting infrastructure allegedly connected to China-sponsored hacking.

In 2025, the FBI removed PlugX malware from more than 4,000 computers in the United States after the devices had been infected by the China-sponsored group Mustang Panda.

In 2024, the FBI disrupted a botnet involving hundreds of thousands of infected IoT devices that investigators said was being provided to Chinese government customers by the group Flax Typhoon.

In 2023, U.S. authorities also disrupted a separate botnet allegedly used by Volt Typhoon to conceal attacks against critical infrastructure in the United States and elsewhere.

The latest action therefore represents another example of the U.S. government targeting the technical infrastructure behind cyber operations.

New Cybersecurity Advisory Released

Alongside the domain seizures, the FBI and National Security Agency published a cybersecurity advisory containing indicators of compromise associated with QTFY.

The advisory is based on analysis of QTFY’s malicious activity dating back to at least 2018.

The information is intended to help network defenders identify potentially malicious activity and protect vulnerable systems.

Lumen Technologies’ threat intelligence group, Black Lotus Labs, also published an analysis of QTFY’s tactics, techniques and procedures.

What the Seizure Means for US Critical Infrastructure

The operation demonstrates a shift toward disrupting cyberattack infrastructure before or during attacks rather than relying solely on traditional investigations after systems have been compromised.

By seizing domains that the malware depended on for communication and authentication, investigators were able to interfere directly with the operation of the alleged hacking platforms.

For organizations responsible for critical infrastructure, the case also highlights the risks posed by compromised internet-connected devices and the importance of monitoring unusual network activity.

The FBI and Justice Department said they will continue using technical operations and legal authorities to disrupt infrastructure associated with state-sponsored cyber threats.

What Happens Next?

The latest action does not end the broader investigation into QTFY or China-linked cyber activity.

Instead, the domain seizures represent one part of an ongoing U.S. effort to identify, disrupt and impose costs on cyber groups accused of targeting American networks.

The publication of indicators of compromise also gives government agencies and private-sector defenders additional information they can use to investigate whether their networks have been exposed to QTFY-related activity.

The Justice Department’s action underscores the continuing U.S. focus on China-linked cyber operations, particularly those involving critical infrastructure and government networks.

Related

Author

Laure Parker

Laurel Parker covers the U.S. health insurance industry, with a focus on health insurance coverage, Medicaid, Medicare, insurance claims, insurance companies and major policy developments. Her work explains complex insurance topics in clear, practical language and follows developments that can affect consumers and families across the United States.

Follow Me
Other Articles
Blake Lively and Justin Baldoni amid their legal dispute over It Ends With Us
Previous

Blake Lively Wins $400,000 in Legal Fees After Justin Baldoni Case

Massachusetts State Rep. Francisco Paulino charged in alleged $700,000 pandemic fraud case
Next

Massachusetts State Rep. Francisco Paulino Charged in $700,000 Pandemic Fraud Case: What Prosecutors Allege

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Insurance Categories

  • Entertainment
  • Health
  • News
  • Political

About & Policies

  • About The Next Coverage
  • Contact Us
  • Disclaimer
  • Fact-Checking Policy
  • Why Trust Us
  • Editorial Policy
  • Privacy Policy
  • Terms of Use
© 2026 The Next Coverage. All Rights Reserved.