Skip to content
See the World Through Science

FBI Seizes Domains and Shuts Down Two Hacking Platforms, Justice Department Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The upper facade and carved stone relief of the Robert F. Kennedy Department of Justice Building in Washington, D.C., against a clear blue sky.
The Robert F. Kennedy Department of Justice Building in Washington, D.C. The department announced the court-authorised domain seizures on Aug. 26."Robert F. Kennedy Department of Justice Building, Washington, D.C" by Pelajanela, via wikimedia, CC-BY-SA-4.0 · CC-BY-SA-4.0

The Justice Department and the FBI have seized internet domains used to run two hacking platforms, QScan and QTRouter, and the court-authorized seizures left both inoperable, the department announced Aug. 26.

The domains had been hard-coded into both pieces of malware and were used for essential tasks including communication and authentication, according to the department, which is why removing them disabled the platforms.

The two tools worked together, the department says. QScan scans for and automatically infects thousands of internet-connected devices worldwide, which are then added to QTRouter, a network that also draws on commercial proxy service devices and leased virtual private servers. QTRouter served as what the department calls an "obfuscation network": it let its operators route traffic so that intrusions appeared to originate from machines outside China, in some cases on the same local networks as the targets.

Court documents unsealed in the Southern District of California say that a state-sponsored group known as QTFY, employed by the China-based Nanjing Xinjiuwei Network Technology Company, created and operated both platforms, according to the department. It says those documents also describe QTFY selling hacking services to paying customers, among them China's Ministry of State Security and the People's Liberation Army. Those assertions are the department's, resting on the unsealed filings.

Among the victims of QTFY intrusion activity, the department names the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Justice Department itself, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.

The FBI and the National Security Agency published a cybersecurity advisory the same day listing indicators of compromise, drawn from analysis of activity the agencies date to at least 2018. Lumen Technologies' Black Lotus Labs separately published its own account of the group's methods.

The department places the operation in a sequence of similar ones: the FBI removed PlugX malware from more than 4,000 computers in the United States in 2025, disabled a botnet of hundreds of thousands of infected devices in 2024, and disrupted another botnet used to conceal intrusions into critical infrastructure in 2023.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

FBI Seizes Domains and Shuts Down Two Hacking Platforms, Justice Department Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.