U.S. authorities say they have disrupted two online platforms allegedly used by Chinese government-backed hackers to probe and attack sensitive American networks. On Aug. 26, the FBI and Justice Department took action against QScan and QTRouter by seizing three domains that court records say were built into the tools’ core communications and authentication systems.

According to the Justice Department, the platforms were used against networks tied to NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. Officials said the tools helped identify vulnerable internet-connected devices and conceal the origin of malicious traffic.

Domains Seized to Disable the Tools

Federal authorities said the operation made both platforms inoperable because the three seized domains were hard-coded into QScan and QTRouter. By cutting off those required connections, investigators were able to interrupt the systems without describing any broader takedown of every element connected to them.

The court filings cited in the case attribute the platforms to QTFY, which the government describes as a Chinese state-sponsored hacking group employed by Nanjing Xinjiuwei Network Technology Company. An FBI affidavit further alleges that QTFY sold hacking services to customers including China’s Ministry of State Security and the People’s Liberation Army.

How QScan and QTRouter Were Used

Officials described the two platforms as parts of a combined reconnaissance, exploitation and traffic-obfuscation setup. In that arrangement, QScan was used to search for weaknesses in exposed systems, while QTRouter helped mask where follow-on activity was coming from.

A joint cybersecurity advisory from the FBI, the National Security Agency and Cyber National Mission Force said QScan contained more than 200 proof-of-concept exploits. The advisory also said the platform handled more than 2 million scanning and penetration-testing tasks in a single day in 2024.

Authorities said QScan could automatically compromise vulnerable devices connected to the internet and then add them to QTRouter. QTRouter reportedly mixed those hijacked devices with commercial proxy services and leased virtual private servers, allowing malicious traffic to appear as if it originated from legitimate users located near the intended targets.

Scope of the Activity Cited by U.S. Agencies

The advisory and court materials point to a large operational footprint. U.S. officials said a campaign in May 2024 exfiltrated data from more than 300 organizations worldwide, though the source article did not specify which entities were affected in that incident.

Attorney General Todd Blanche said federal law enforcement had investigated and disabled what he called malicious software tied to the People’s Republic of China. FBI Director Kash Patel separately described the action as a disruption of a global botnet and hacking platform used to target U.S. critical infrastructure and to obscure the origin of attacks.

What Happens Next

The confirmed step so far is the seizure of the three domains that authorities say were essential to both platforms. Based on the Justice Department’s account, that action was intended to stop QScan and QTRouter from continuing to authenticate and communicate as designed.

Beyond the domain seizures, the public record cited here focuses on the alleged functions of the tools, the agencies said to have been targeted, and the government’s attribution of the operation to QTFY. Further legal or technical actions were not detailed in the source material.

Source: news.bitcoin.com