The Department of Justice (DOJ) and FBI have seized domains essential to two hacking platforms operated and used by Chinese hackers to target U.S. critical infrastructure and other sensitive networks.
The DOJ said on Aug. 26 that the court-authorized seizures denied malicious cyber actors access to QScan and QTRouter, two platforms created and operated by a Chinese state-sponsored hacking group known as “QTFY.”
Because the seized domains were hard-coded into the malware for essential functions including communications and authentication, the operation made both platforms inoperable, the department said.
The DOJ identified NASA, the Federal Reserve, the Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), the U.S. Senate, and its own department as victims of QTFY computer-intrusion activity.
An FBI affidavit says QTFY infrastructure has been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and around the world, including networks operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
In 2024 alone, QScan processed more than 2 million scanning and exploit tasks. According to the FBI, QTFY successfully exploited a vulnerability in Check Point Quantum Gateway products and stole server-configuration files and user-account details from more than 300 U.S. organizations.
That September, QTFY actors conducted zero-day intrusions at three Department of Energy national laboratories, the NIH, another HHS agency, and a U.S. security-device manufacturer and remotely accessed all six, according to the affidavit.
Automated Exploitation at Scale
The court filing describes QScan as a platform built to find vulnerable systems and exploit them.
Its capabilities included scraping webpages, collecting digital security certificates, identifying subdomains, and performing penetration-testing tasks.
For penetration testing, QScan contained a database of more than 200 proof-of-concept exploits written in Python, according to the affidavit.
The platform distributed scanning and exploitation tasks through remote worker servers and collected the results through separate infrastructure.
The Check Point intrusion occurred after a vulnerability known as CVE-2024-24919 became public in May 2024.
The affidavit says QTFY successfully exploited the vulnerability several days later and obtained sensitive information from targeted systems, including server configuration files and user-account details.
The September 2024 operation targeted a different vulnerability.
Investigators said QTFY actors exploited a previously unknown vulnerability in the Ivanti Cloud Services Appliance and used the same IP address to remotely access the government entities and U.S. manufacturer.
Hiding Attacks Behind Other Devices
QScan worked in conjunction with QTRouter, infrastructure designed to conceal the origin of malicious cyber activity.
According to the DOJ, QScan scanned for vulnerable internet-connected devices around the world and automatically infected thousands of them. Those compromised devices were then incorporated into QTRouter.
The network also used commercial proxy services and leased virtual private servers, allowing hackers operating from China to route their communications through devices elsewhere.
The DOJ said the arrangement could make an attack appear to originate outside China—and potentially from a device geographically close to the targeted network.
The FBI affidavit says QTRouter combined custom router devices, commercial proxies, VPNs, and compromised internet-connected devices to disguise the origin of its malicious traffic.
Private Cybersecurity and the Chinese Regime
The DOJ said QTFY was employed by Nanjing Xinjiuwei Network Technology Company, a Chinese cybersecurity company.
According to the department, QTFY offered computer-hacking services to paying customers that included the Chinese regime’s Ministry of State Security and People’s Liberation Army.
The filing says payments from the Ministry of State Security to Nanjing Xinjiuwei indicate that the company conducts malicious cyber activity on behalf of the Chinese regime.
It also says QTFY includes former People’s Liberation Army members who use their relationships with the military to obtain contracts and subcontracts supporting offensive cyber operations.
The public affidavit does not identify which, if any, customer to the regime directed each of the individual U.S. intrusions described in the filing.
Domains Seized
The FBI sought warrants for three domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—that investigators said were used to operate QScan and QTRouter.
The affidavit called for the relevant domain registries to lock the domains and associate them with servers designated by the FBI.
This follows previous FBI disruptions of infrastructure used by Chinese regime-sponsored hacking groups including Mustang Panda, Flax Typhoon, and Volt Typhoon.
On Aug. 26, the FBI and National Security Agency also published cybersecurity guidance containing indicators of compromise based on their analysis of malicious QTFY activity dating back to at least 2018, according to the DOJ.

