US Seizes Domains Linked to QScan and QTRouter Platforms Associated with QTFY
US authorities took the domains of the QScan and QTRouter platforms offline. According to the DOJ, they were used by the Chinese group QTFY to scan for vulnerabilities and conceal traffic.

QTFY domain seizure was announced on August 26 by the US Department of Justice (DOJ) and the FBI. Under court authorization, they took control of domains used by the QScan and QTRouter platforms, which the DOJ said were operated by the Chinese group QTFY. US authorities said this took both platforms offline.
The case is significant because it did not involve just a single malicious server. According to a joint advisory from the FBI, NSA, and Cyber National Mission Force, the infrastructure covered multiple phases of cyber operations: QScan was used to find and exploit vulnerabilities, while QTRouter provided a masking network for further communications.
QTFY domain seizure hit reconnaissance and proxy infrastructure
The US advisory describes QScan as a tool designed to automatically scan internet targets and attempt to exploit identified weaknesses. QTRouter, by contrast, was reportedly used to hide the origin and routing of activity. It reportedly used compromised Internet of Things devices, commercial proxy services, and virtual private servers.
This combination allows attackers to first identify potentially vulnerable systems and then communicate through distributed infrastructure. For security teams, this makes it more difficult to distinguish malicious traffic from normal internet activity, especially when communications come through legitimate cloud or proxy services.
The DOJ attributes QTFY to the Chinese company Nanjing Xinjiuwei Network Technology Company. According to the department, its customers included China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA). This is an attribution by US authorities based on an investigation and court documents; complete independent public verification of all these findings is not available.
Federal institutions and NASA among listed targets
The DOJ listed NASA, the Federal Reserve, the Departments of Justice and Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate among the victims of activity attributed to QTFY. However, the published materials do not specify the extent of any access, stolen data, or the specific impact on the networks of individual organizations.
It is particularly important to distinguish scanning from successful intrusion. The joint government advisory states that QTFY scanned the US Senate in March 2026, but the attempt to gain access to the network was unsuccessful. It is therefore not accurate to claim that the group breached all organizations named in the DOJ announcement.
The seizure of QTFY domains may limit attackers’ ability to use established command-and-control and masking channels. By itself, however, it does not mean that all related servers, devices, or compromised IoT elements have been removed. Nor does it automatically clean networks that attackers may have accessed before the action.
What network administrators should check
The FBI, NSA, and Cyber National Mission Force published indicators of compromise and recommended mitigations along with the advisory. Organizations should use this information for retrospective reviews of logs, network traffic, and systems exposed to the internet.
- Update software and firmware, especially on internet-accessible devices.
- Review VPNs, IoT devices, and remote-management interfaces that may provide an entry point.
- Separate critical systems from edge devices and restrict unnecessary direct connections.
- Compare internal telemetry with the published indicators of compromise.
Going forward, it will be important to see whether the FBI or DOJ supplement the court documents and clarify which organizations experienced successful access. It will also become clear whether QTFY restores its infrastructure under new domains or changes its techniques and indicators.
Sources
- U.S. Department of Justice – Confirms the seizure of the domains on August 26, 2026, the attribution of QScan and QTRouter to the QTFY group, and the list of organizations that the DOJ identifies as victims of the activity.
- FBI, NSA, and Cyber National Mission Force – Joint Cybersecurity Advisory – Provides more detail on the attack timeline, including the unsuccessful attempt to access the US Senate network in March 2026, and lists IoCs and recommended mitigations.
- National Security Agency – Confirms the release of the joint advisory and describes the functions of QScan, QTRouter, and related botnet platforms.
- Lumen Black Lotus Labs – Provides independent telemetry observations of the QScan and QTRouter architecture and related proxy infrastructure.
Verified and updated: 08/27/2026 18:53



