At a Glance
| Actor/Group | QTFY, a PRC state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company |
| Activity | Reconnaissance, obfuscation, and hacking-as-a-service via the QScan and QTRouter platforms |
| Victims | NASA, Federal Reserve, U.S. Senate, and the Departments of Energy, Justice, and Health and Human Services |
| Scale | Activity dating to at least 2018; QScan allegedly processed over 2 million tasks in a single day in 2024 |
| Status | Three domains seized in the Southern District of California; platforms now inoperable |
| Source | U.S. Department of Justice; Lumen Black Lotus Labs |
TL;DR
The Justice Department and FBI seized platforms run by China state-sponsored hackers to mask attacks on U.S. critical infrastructure. The two tools, QScan and QTRouter, let a group known as QTFY hide the origin of its intrusions. Researchers at Lumen Black Lotus Labs traced the network to a private “quartermaster” that rents stealth infrastructure to other actors.
What Happened
On August 26, 2026, the DOJ announced court-authorized domain seizures. The move targeted two linked hacking platforms, QScan and QTRouter. According to the Justice Department press release, the seizures rendered both tools inoperable.
The two platforms played different roles. QScan scanned the internet and infected thousands of IoT devices. QTRouter then folded those devices into an “obfuscation network.” As the DOJ explained, that network let the actors conceal “the PRC-origin of their computer intrusion activities.”
Because the seized domains were hard-coded into the malware for tasks like authentication, cutting them off broke the platforms. All three domains now display a law enforcement banner.
Who Is Behind It
U.S. authorities attribute the platforms run by China state-sponsored hackers to a group called QTFY. Court documents say QTFY worked through Nanjing Xinjiuwei Network Technology Company. The attribution comes with high confidence, backed by an unsealed FBI affidavit.
The DOJ alleges QTFY sold hacking services to paying clients. Those clients allegedly included China’s Ministry of State Security and the People’s Liberation Army. Court filings also state there is probable cause to believe the domains supported a money-laundering conspiracy. No one has been convicted, and these remain allegations.
The Quartermaster Model
Black Lotus Labs spent about a year tracking the operation. Its report frames QTFY as an infrastructure “quartermaster.” The team writes that “the infrastructure they use can matter as much as the tools for gaining access.”

The model rests on four parts. QScan handles reconnaissance. Fast Labyrinth relays and hides traffic. QTRouter manages access. QTProxy coordinates the proxy nodes. Notably, the operators skipped building a botnet from scratch. Instead, they bought premium access to a Chinese commercial proxy service to blend espionage traffic with ordinary consumer streaming.
Impact and Scale
The victim list is striking. It includes NASA, the Federal Reserve, and the U.S. Senate. The Departments of Energy, Justice, and Health and Human Services also appear, along with the National Institutes of Health.
The operation ran at industrial scale. An FBI affidavit states that on one day in 2024, QScan processed over two million scanning and exploit tasks. Black Lotus Labs found heavy targeting of research universities in advanced physics, aerospace, and bioinformatics. U.S. military and defense supplier networks drew close profiling.
What Comes Next
This action joins a run of U.S. takedowns against PRC hacking crews. Similar operations hit Volt Typhoon, Flax Typhoon, and Mustang Panda in recent years. The FBI and NSA also released an advisory with indicators of compromise for QTFY activity dating to 2018.
Defenders should review that advisory and hunt for the listed indicators. Patching internet-facing devices remains critical, since QScan hunted for unpatched systems. Watch outbound connections to unfamiliar proxy nodes. Domain seizures disrupt operators, but shared infrastructure models can rebuild, so vigilance still matters.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!