Nation-state hacking increasingly looks like a vendor relationship. According to a Justice Department announcement made public on August 26, a China-based group US officials call QTFY did not just run intrusions for Beijing. It built and sold two hacking platforms, QScan and QTRouter, to paying customers that included China’s Ministry of State Security and the People’s Liberation Army.

A contractor, not just a cell

The Justice Department and FBI announced court-authorized domain seizures on August 26 that disabled QScan and QTRouter, tools built by a China-based company, Nanjing Xinjiuwei Network Technology Company, and operated by QTFY. According to court documents unsealed in the Southern District of California, QTFY offered its hacking services commercially, and its client list included the PRC’s Ministry of State Security and the People’s Liberation Army.

That structure sets QTFY apart from earlier PRC-linked campaigns the US has disrupted. QScan automatically scanned and infected internet-of-things devices worldwide, feeding them into QTRouter, a network of compromised devices, commercial proxy services, and leased virtual private servers that functioned as what DOJ calls an obfuscation network. Traffic routed through QTRouter appeared to originate from devices outside China, sometimes inside the very networks the attackers were targeting, making attribution and blocking far harder for defenders on the receiving end.

Media Partner

Web3 x AI Fusion — Media Partner

Among the organizations QTFY’s customers targeted, according to DOJ: NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

Why the takedown worked, for now

The seizure was effective because the domains DOJ took were hard-coded into the QScan and QTRouter malware for essential functions, including command communication and authentication. Removing them made both platforms inoperable in a single action, without needing to individually remediate every infected device around the world.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” said Attorney General Todd Blanche.

FBI Director Kash Patel framed the action as part of a broader campaign rather than a one-off: “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down.”

A pattern, and a limit

QTFY’s disruption is the fourth in a run of similar technical operations against PRC-sponsored infrastructure. DOJ’s own release points to the FBI removing PlugX malware from more than 4,000 US computers infected by Mustang Panda in 2025, dismantling a Flax Typhoon IoT botnet in 2024, and disrupting Volt Typhoon’s obfuscation network in 2023. CyberTech has argued before that legal action against state-linked hacking groups rarely stops the underlying activity, since the operators, and often the infrastructure model, survive to be rebuilt. QTFY’s contractor structure, selling access rather than running a single campaign, makes that risk more acute: a seized botnet can be replaced by a new one built on the same commercial relationship with the Ministry of State Security and the PLA. Treasury’s sanctions against Iranian hackers this week reflect a similar strategy from a different agency, using financial and legal levers against actors whose operational capability is otherwise hard to reach directly.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

Separately, the FBI and NSA published a joint cybersecurity advisory with indicators of compromise based on QTFY activity dating back to at least 2018, and Lumen Technologies’ threat intelligence group, Black Lotus Labs, published its own analysis of the group’s tactics, techniques, and procedures.

What it means for the security leader

The QTFY case is a reminder that an IoT botnet and a nation-state advanced persistent threat are not separate categories of risk anymore. Any internet-facing IoT device on a network, a camera, a router, a building controller, is a candidate to be silently absorbed into an obfuscation network like QTRouter and used to launder traffic aimed at someone else’s critical infrastructure. Security leaders should treat unmanaged IoT and edge devices as potential relay points, not just endpoints: unusual outbound connections from devices that have no legitimate reason to initiate them are a stronger signal than inbound traffic alone, and asset inventories that stop at laptops and servers are missing the category of device this case actually turned on.

For organizations in the sectors DOJ named as QTFY targets, federal government, health research, and financial regulation among them, the joint FBI and NSA advisory’s indicators of compromise are worth checking against network logs now, not filing away for later. A domain seizure buys time by disabling the infrastructure a group depends on today. It does not close the access, or the commercial relationship between the operator and its state customers, that made a given target attractive in the first place. The next platform QTFY, or a group like it, brings to market will need a different technical foothold, and it is that foothold, not the seized domains, that a defender’s monitoring should be built to catch.

There is also a procurement lesson buried in the DOJ filing that is easy to miss. QTFY sold access the way a legitimate managed-security vendor sells a subscription, with a stable platform, a customer list, and repeat business from the Ministry of State Security and the PLA. Treating a nation-state group as a vendor with its own supply chain, rather than as a single opaque adversary, opens up a different kind of pressure: disrupt the platform once, as DOJ did here, and every one of QTFY’s paying customers loses capability at the same time, not just the operators who happened to be running an active campaign that week.

Source: Department of Justice