Key takeaways
- The Justice Department announced court-authorized domain seizures on August 26, 2026; the release was updated on August 28 to clarify that its statements reflect allegations in the supporting affidavit.
- The government alleges that QScan performed internet-scale reconnaissance and exploitation tasks, while QTRouter obscured intrusion traffic through compromised IoT devices, commercial proxies and leased infrastructure.
- The joint federal advisory identifies energy, water and wastewater, communications, government, IT and defense-related organizations among the audiences and sectors needing to review the threat information.
- Facilities and enterprise defenders should prioritize externally exposed edge devices, unsupported systems, web applications and the separation of critical systems from internet-facing or edge-connected networks.
- Organizations should hunt the published indicators before blocking them indiscriminately, since the advisory includes both historical and current infrastructure.
Federal action targets two connected platforms
The U.S. Department of Justice and FBI announced on August 26 that they had executed court-authorized seizures of domains associated with QScan and QTRouter. According to the Justice Department, the action was intended to deny operators access to platforms used to target U.S. critical infrastructure and other sensitive networks. The department updated its release on August 28, stating that edits were made to ensure it accurately reflected the government’s allegations in the affidavit supporting the seizures.
The government attributes the activity to a China-linked group it calls QTFY and alleges that the group was operated through Nanjing Xinjiuwei Network Technology Company. These are government allegations, not findings of a criminal trial. The joint FBI, NSA and Cyber National Mission Force advisory says the group has been active since at least 2018 and has targeted organizations in the United States and abroad.
Why QScan and QTRouter worked together
Federal investigators describe QScan as a distributed scanning and exploitation environment. The advisory says it handled tasks including web scraping, TLS certificate collection, subdomain enumeration and penetration testing. It reportedly contained more than 200 Python proof-of-concept exploits and processed more than two million scanning and penetration-testing tasks on one day in 2024.
QTRouter is described as the complementary traffic-obfuscation layer. It allegedly used a mix of compromised IoT devices, commercial proxy-service nodes and leased virtual private servers to make malicious connections appear to originate from systems outside China, potentially including systems geographically close to a target. This matters because source IP reputation alone may offer an incomplete basis for allowing or denying access.
DOJ says the seized domains were hard-coded into QScan and QTRouter malware and were necessary for functions including communication and authentication. On that basis, the department said the seizures rendered both platforms inoperable. The action disrupts the identified infrastructure, but it should not be treated as proof that the underlying operators, tooling or future infrastructure have been eliminated.
Critical-infrastructure targeting raises an edge-security concern
The federal advisory identifies critical-infrastructure sectors including communications, energy, water and wastewater, information technology, government services and facilities, and the defense industrial base. Its historical activity timeline includes scanning or exploitation attempts involving U.S. government entities, power and telecommunications companies, a water district, healthcare organizations, educational institutions and private-sector firms.
For industrial organizations, the relevant pattern is not limited to a particular brand of router, firewall or remote-access appliance. QTFY activity described by the agencies centers on finding and exploiting externally reachable systems, including VPNs, web applications, content-management components and network-management devices. The advisory also describes the use of remote-access trojans, web shells and legitimate credentials after initial access.
That makes an accurate asset inventory particularly important. Security teams need to know which internet-facing systems exist, who owns them, their firmware and software versions, whether they are supported, and which paths—intended or accidental—connect enterprise edge environments to operational technology or critical control networks.
Actions for facilities, OT and network teams
First, review public exposure. Confirm that remote administration, web interfaces, VPN gateways, cloud-management services and vendor-maintenance pathways are necessary, current and protected by strong authentication. Remove or restrict obsolete services, and ensure web-server software and plugins receive timely updates. The agencies specifically advise organizations to identify end-of-support devices and use lifecycle processes to replace them.
Second, test segmentation in practice. The advisory calls for isolating critical systems from edge devices using zero-trust segmentation principles. For a facility environment, this means validating that a compromise of an internet-facing device, building-network component or office-network endpoint cannot provide a straightforward route to controllers, engineering workstations, supervisory systems or sensitive operational data.
Third, reduce information exposed through public sites and applications. The federal guidance recommends auditing pages and applications for accidentally published secrets, such as API keys, tokens and sensitive configuration details. Procurement and engineering teams should include this review in vendor portal, remote-support and cloud-service assessments, not just traditional IT security reviews.
Use the indicators carefully and prepare response steps
The FBI, NSA and Cyber National Mission Force published downloadable QTFY indicators of compromise alongside the advisory. These include domains, IP addresses and file hashes associated with QScan, QTRouter and related tooling. The agencies caution that some indicators correspond to historical activity and recommend investigation or vetting before defensive actions such as blocking.
Teams should load the indicators into DNS, proxy, firewall, endpoint and network-monitoring workflows as appropriate, then search retained logs for historical connections and associated behavior. The advisory maps the reported activity to techniques including vulnerability scanning, exploitation of public-facing applications, web-shell persistence, virtual private server acquisition and in-house capability development.
If a credible compromise is identified, the agencies recommend first determining affected hosts and isolating them, then conducting threat hunting to establish scope and timeline before applying eviction measures. Organizations should preserve relevant evidence, coordinate incident response across IT and OT stakeholders, and report incidents to the FBI or other appropriate authorities.
A disruption event, not a reason to defer hardening
The seizures remove access to infrastructure that the government says was central to QScan and QTRouter operations. That is a meaningful defensive outcome, especially where hard-coded domains were required by the malware. However, the accompanying advisory shows why the immediate operational lesson is broader: attackers can pair automated reconnaissance with rotating infrastructure, compromised connected devices and proxy services to conceal the origin of activity.
For integrators, operators and security engineers, the practical response is to use this event as a validation exercise. Reconcile the external asset inventory, verify firmware and end-of-support status, review remote-access architecture, test segmentation boundaries and hunt the supplied indicators. These measures improve resilience whether the observed traffic is tied to this specific activity or to the next campaign using a different set of domains and proxy nodes.
Sources
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure — U.S. Department of Justice
- China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems — Federal Bureau of Investigation; National Security Agency; Cyber National Mission Force
- Inside China-nexus cyber espionage infrastructure — Lumen Technologies Black Lotus Labs
