Overview
- Federal prosecutors and the FBI on Wednesday, Aug. 26 seized internet domains the Justice Department says were essential to two hacking platforms called QScan and QTRouter, rendering those systems inoperable and disrupting a global botnet.
- Court filings identify the operator as a China‑linked group called QTFY that worked through Nanjing Xinjiuwei Network Technology Company and sold services to customers the filings name as the Ministry of State Security and the People’s Liberation Army.
- According to the affidavit, QScan scanned for and automatically infected thousands of internet‑connected devices worldwide and QTRouter routed malicious traffic through those compromised devices to hide where attacks came from.
- U.S. filings list victims including NASA, the Federal Reserve, the Department of Justice, the U.S. Senate, the Department of Energy, HHS and NIH and also say hospitals, telecoms, power firms, financial firms and defense contractors were targeted; the DOJ has not disclosed the full extent of data taken or damage.
- Officials describe the seizure as the latest court‑authorized technical disruption of alleged PRC‑linked cyber tools, say investigations and mitigation work continue, and Beijing has formally rejected the U.S. allegations.