Off air

Tech · FBI shuts QScan factory

FBI Cut Power to a Chinese Hacking Factory That Ran 2 Million Tasks a Day

The Justice Department says it seized domains behind QScan and QTRouter, tools built to find victims at scale and hide the attack path into NASA, the Senate, DOE and the Fed.

Transcript · loading player

Two million tasks in a single day. That is the number that makes the FBI case against a Chinese state-sponsored hacking operation comprehensible, not as a handful of break-ins but as factory output 8. The scanning never paused for a human to decide what to hit next. It mapped, probed and fired, day after day, until the intrusions that followed could look routine, local and almost invisible.

On Wednesday, August 26, 2026, the Justice Department and FBI announced court-authorized seizures of internet domains behind two complementary hacking platforms, described as “QScan” and “QTRouter,” used by China state-sponsored hackers to target U.S. critical infrastructure 2. The FBI said it had disrupted a botnet and seized two platforms used to hack NASA, the U.S. Senate, the Department of Energy, the Federal Reserve, and other agencies and critical networks 4.

The operation was aimed at a state-sponsored group called QTFY, also known as QT, QTCWIBER, and Quantum Typhoon, attributed to the China-based company Nanjing Xinjiuwei Network Technology Co. 6 8. QTFY has sold hacking services to the PRC’s Ministry of State Security and the People’s Liberation Army 8. CyberScoop reports the full hacking suite allowed Chinese government-funded attackers to intrude into highly sensitive networks undetected for more than eight years 5.

an industrial-scale scanning-and-exploitation business that ran two million tasks in a single day

That industrial description matters because the two seized platforms did different jobs. QScan is described as a scanning-and-exploitation layer, built to find vulnerable systems at internet scale and then attempt intrusion 8. QTRouter is the obfuscation layer, routing attack traffic through compromised devices to disguise origins 2 9. SecurityAffairs confirms the two platforms were used to hide intrusions and target U.S. critical infrastructure 9.

Taken together, they solved the two hardest problems for a long-running espionage campaign: how to find the next opening without being seen looking, and how to walk through it without appearing to come from China. The scan finds the weakness. The router hides the approach. By the time a victim logs an intrusion, the source address points somewhere ordinary and the method looks like background internet noise.

The victim list disclosed so far is narrow but unusually sensitive. Reuters reports Chinese hackers broke into the Justice Department, NASA, the Federal Reserve, and the Senate 3. The Register adds the Department of Energy 4. Those are not peripheral networks. They include law enforcement, monetary policy, space and scientific research, legislative communications, and energy and nuclear-security equities.

Seizure aimed to deny access

The Justice Department framed the August 26 action as a technical seizure rather than an arrest or indictment announcement. The DOJ and FBI stated the seizures were intended “to deny malicious cyber actors access” to the platforms 2. In practice, that meant using court authority to take control of domains the platforms depended on, cutting the operators’ path back into their own infrastructure.

A Joint Cybersecurity Advisory, JCSA-20260826-01, was released August 26, 2026 by the FBI, NSA, and Cyber National Mission Force 10. The coordinated advisory signals that the government treated this as more than a one-day law-enforcement action. It was also a warning to defenders: here is the infrastructure, here is how it worked, look for it on your networks.

The central unresolved question is durability. Coverage of the disruption raised the same issue that follows almost every botnet takedown: whether removing the domains permanently blinds the network or leaves thousands of still-infected devices ready to be rebuilt 5. A seizure that breaks command and control does not automatically clean compromised routers, cameras, servers or other edge devices, and operators with eight years of investment have strong incentives to rebuild.

That durability question is sharpened by the group’s business model. This was not described as a lone crew renting servers. QTFY was attributed to a company, Nanjing Xinjiuwei Network Technology Co., and accused of selling hacking services to intelligence and military customers 6 8. A contractor that sells access can treat a takedown as a cost of doing business, as long as its methods, personnel and customer relationships survive.

The eight-year timeline is therefore as important as the two-million-task day 5 8. Eight years allows tooling to mature, targeting lists to accumulate, and intrusions to be staged slowly enough to avoid alarms. It also means many victim organizations may still not know what was taken, when persistence was established, or whether a later intrusion used credentials stolen much earlier.

Known

  • On Aug. 26, 2026, DOJ and FBI seized domains behind “QScan” and “QTRouter” to deny actors access. 2
  • QTFY is attributed to Nanjing Xinjiuwei Network Technology Co. and sold services to the MSS and PLA. 8
  • Named intrusion targets include NASA, the Senate, DOE, Federal Reserve and other critical networks. 4

Unknown

  • Whether the domain seizures permanently disable the platforms or allow a rebuild with new infrastructure.
  • What data was stolen, whether persistent access remains, and the full victim scope beyond named agencies.

Next

  • Whether defenders find QTFY artifacts using the joint advisory and whether replacement infrastructure appears.

What is missing from the public record is as telling as what was announced. The available reporting does not specify the exact names of the seized domains, verbatim official quotes from named officials, or the full scope of damage and persistence inside victim networks. It also does not independently confirm broader figures and links discussed around the case, including worldwide routing claims, a company founding year, or alleged freelance-network ties.

That restraint should guide how the August 26 announcement is read. The confirmed core is significant on its own: two platforms, one for finding victims at scale and one for hiding the attack path, operated for years on behalf of state customers and aimed at some of the most sensitive U.S. networks 2 8 9. The seizure disrupts that arrangement without proving it has ended 2 5.

For network defenders, the practical message comes from the joint advisory process itself. An advisory numbered JCSA-20260826-01 and issued by three U.S. agencies on the same day as the seizure gives organizations a place to start hunting, even while the larger questions about data loss and reconstitution remain open 10. The next measure of success will not be the press release. It will be whether the scanning factory stays quiet.

Sources

  1. FBI Seizes Botnet That Routed China Attacks Through 130 CountriesHeyDay News · video
  2. Office of Public Affairs | Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure | United States Department of Justicewww.justice.gov
  3. US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate | Reuterswww.reuters.com
  4. FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networkswww.theregister.com
  5. Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoopcyberscoop.com
  6. US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks - SecurityWeekwww.securityweek.com
  7. FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate - Help Net Securitywww.helpnetsecurity.com
  8. The Scan Factory: Inside China's QTFY Hacking Group | SafeBreachwww.safebreach.com
  9. FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructuresecurityaffairs.com
  10. QTFY: SafeBreach Coverage for JCSA-20260826-01 | SafeBreach Coveragewww.safebreach.com
  11. FBI, DOJ Seize China's QScan and QTRouter Hacking Toolswww.thecybersignal.com

Revision log

  1. r1First published.