Overview
- The Justice Department and FBI announced they seized three internet domains on Wednesday, Aug. 26, 2026, and said the action rendered the QScan and QTRouter platforms inoperable.
- Court filings and an affidavit attribute the platforms to a group called QTFY that investigators tie to Nanjing Xinjiuwei Network Technology Company and say it sold services to China’s Ministry of State Security and the People’s Liberation Army.
- U.S. officials named high‑value victims including the Federal Reserve, NASA, the Department of Justice, the Department of Energy, HHS, the NIH and the U.S. Senate, and said private targets included hospitals, telecoms, power companies and defense contractors.
- The government says QScan scanned and automatically infected thousands of internet‑connected devices to build a botnet and QTRouter routed attack traffic through those devices to hide the true origin of intrusions.
- Authorities say the seizure disrupts the group’s tooling but investigations are ongoing and agencies have not disclosed the full extent of any data theft or historical access, leaving operational and diplomatic questions to be resolved.