US DOJ Takedown of Chinese QScan, QTRouter
The U.S. Department of Justice dismantled the QScan and QTRouter hacking platforms linked to Chinese state-backed attacks on federal agencies, citing investigations that began in 2018.

The United States Department of Justice announced on Wednesday that it had taken down the QScan and QTRouter hacking platforms used by China-based Nanjing Xinjiuwei Network Technology Company. The takedown follows investigations that trace the tools to attacks on the Federal Reserve, the Department of Energy, the DOJ, the U.S. Senate and NASA since 2018.
Tools and Operators
The DOJ affidavit says the tools were operated by the China Ministry of State Security and the People’s Liberation Army. QScan was used to scan and automatically infect Internet-of-Things devices worldwide, while QTRouter acted as an obfuscation network that made attacks appear to originate from infected devices. The platforms were run by the state-sponsored group known as “QTFY,” which targeted U.S. critical infrastructure and other sensitive networks. FBI Assistant Director Brett Leatherman said QTFY exploited devices in more than 130 countries and “operates within a complex network of hackers-for-hire and government clients in China.”
Nanjing Xinjiuwei “sells stolen data and hacking services to Chinese military and intelligence agencies,” Leatherman added. “Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet or a network of machines secretly controlled by the adversary.”
Targeted Agencies
The DOJ affidavit lists a broad range of victims. The following table shows the agencies and organizations that were targeted by QScan and QTRouter:
The DOJ did not specify which senators or Senate committees were attacked in the 2024 incident.
Takedown Impact
The FBI and DOJ said the seizure of the domains that were hard-coded into both QScan and QTRouter made the platforms inoperable. Those domains were essential for communication and authentication. The takedown also disrupted the botnet that fed infected devices into the network.
The DOJ said the takedown made both QScan and QTRouter inoperable because the seized domains were hard-coded into both platforms and used for essential tasks like communication and authentication stats. The FBI added that QTFY had unspecified customers outside of the Chinese government squad.
Investigation History
Investigators have tracked QTFY’s infrastructure since 2018, continuing until a Senate attack that occurred this year. One of the earliest incidents investigated by the FBI was a 2019 NASA attack that exploited a Pulse Secure VPN vulnerability. IP addresses used in that attack were traced back to locations and email addresses in China.
The Justice Department and FBI have repeatedly targeted similar platforms used by state-backed hackers to obfuscate attacks on U.S. institutions. In 2023, U.S. law enforcement obtained court orders that allowed agents to remove malware installed by Chinese and Russian actors from devices. Last year, the FBI removed the PlugX surveillance malware from thousands of U.S. computers and disrupted multiple botnets run by Chinese government hacking operations known as Volt Typhoon and Flax Typhoon.
The DOJ did not respond to requests for comment.





