The Justice Department and FBI obtained court orders to seize domains used by QScan and QTRouter on August 26. The U.S. attributes the platforms to a group called QTFY, associated with China-based Nanjing Xinjiuwei Network Technology.
DOJ alleges that the company's paying customers included China's Ministry of State Security and People's Liberation Army. Beijing disputes the broader U.S. attribution. A Chinese Embassy spokesperson told Reuters that China opposes cyberattacks and accused Washington of using cybersecurity allegations to discredit the country. The company itself had not responded to Reuters when its report was published.
This was closer to an infrastructure service than one hacking tool
The joint NSA, FBI and Cyber National Mission Force advisory describes QScan as a reconnaissance and exploitation platform. It could identify vulnerable internet-facing systems, exploit exposed IoT devices and help locate weaknesses that could be useful for later intrusion attempts.
Lumen's Black Lotus Labs tracked a broader ecosystem around the same operation. Its telemetry shows distributed scanning workers receiving jobs from central infrastructure and returning network information for aggregation. The result was a reusable map of exposed services rather than a one-off scan of a single target.
That distinction matters. A patient operator can watch an organization's perimeter over time, notice a newly exposed service or version change, and decide when a target becomes worth further attention.
The U.S. advisory says QTFY used both zero-day and already-known vulnerabilities and also obtained legitimate credentials from compromised systems to maintain access.
The relay layer solved an attribution problem
QTRouter provided the other half of the operation. DOJ says its obfuscation network included compromised IoT devices, devices associated with commercial proxy services and leased virtual private servers.
An intrusion routed through that infrastructure no longer had to expose a source address in China. The last visible connection could originate from another country or from an address physically close to the victim.
Black Lotus Labs describes additional components around the relay service, including QTProxy and a proxy network it calls Fast Labyrinth. Some of the infrastructure incorporated commercial proxy capacity, allowing malicious sessions to hide among high volumes of ordinary consumer traffic.
That model is useful to more than one operator. Instead of every intelligence contractor maintaining its own global set of compromised routers and proxies, a specialized infrastructure provider can supply reconnaissance and routing as a reusable layer.
Hard-coded domains gave investigators a choke point
Decentralized infrastructure still needs control systems. According to DOJ, domains seized in the operation were hard-coded into QScan and QTRouter and were required for essential functions including communications and authentication.
The government says taking control of those domains made both platforms inoperable.
That is not the same as erasing every compromised IoT device or permanently removing the people behind the service. New domains and new control infrastructure can be built. The immediate effect is to break an established operational network and force its users to rebuild or replace it.
Not every government name in the case represents a successful breach
The public filings and press releases reference sensitive targets including NASA, the Federal Reserve, the Justice Department, Department of Energy facilities, HHS, NIH and the U.S. Senate. The underlying record distinguishes successful compromises from unsuccessful attempts.
Reuters reports that an attempt against a NASA VPN vulnerability in August 2019 failed. Scanning and attempted access against the U.S. Senate and a U.S. hospital in March 2026 were also unsuccessful.
Other activity did result in intrusions. Court documents cited by Reuters describe compromises at three Energy Department laboratories, NIH, an HHS agency and a U.S. security-device manufacturer in September 2024. The joint cybersecurity advisory also describes successful data theft from unnamed defense contractors, financial institutions and universities in May 2024.
That makes the terminology important: scanning a network, attempting exploitation, obtaining access and stealing data are different stages and should not be collapsed into one claim that every listed organization was fully breached.
The defensive advice is mostly mundane, which is part of the problem
The NSA and FBI recommend current firmware and software updates, regular audits of internet-facing applications, isolation of critical systems from edge devices and threat hunting using the indicators included with the advisory.
Routers and IoT equipment are particularly attractive relay nodes because they can remain online for years while receiving less monitoring than servers and employee endpoints. Once compromised, they provide a legitimate-looking internet connection that defenders may otherwise treat as ordinary traffic.
The U.S. agencies trace QTFY activity back to at least 2018. Their August 26 advisory now gives network defenders indicators that can be checked against historical DNS, proxy and traffic records rather than only against currently active infrastructure.