Particle.news
Download on the App Store

U.S. Seizes Domains Behind QScan and QTRouter Used in China‑Linked Hacks of Federal Networks

Seizing the domains cuts off the botnet controls that U.S. officials say were run from Nanjing.

Overview

  • The Justice Department and FBI announced they seized three internet domains on Wednesday, Aug. 26, 2026, and said the action rendered the QScan and QTRouter platforms inoperable.
  • Court filings and an affidavit attribute the platforms to a group called QTFY that investigators tie to Nanjing Xinjiuwei Network Technology Company and say it sold services to China’s Ministry of State Security and the People’s Liberation Army.
  • U.S. officials named high‑value victims including the Federal Reserve, NASA, the Department of Justice, the Department of Energy, HHS, the NIH and the U.S. Senate, and said private targets included hospitals, telecoms, power companies and defense contractors.
  • The government says QScan scanned and automatically infected thousands of internet‑connected devices to build a botnet and QTRouter routed attack traffic through those devices to hide the true origin of intrusions.
  • Authorities say the seizure disrupts the group’s tooling but investigations are ongoing and agencies have not disclosed the full extent of any data theft or historical access, leaving operational and diplomatic questions to be resolved.