DOJ Disrupts QScan, QTRouter Platforms Used by Chinese State Hackers
It's the third court-authorized disruption of PRC hacking infrastructure targeting U.S. critical infrastructure in 18 months, and the sequence is no longer experimental.
TL;DR
DOJ and FBI announced court-authorized domain seizures to deny Chinese state-sponsored hackers access to QScan and QTRouter, two complementary hacking platforms used to target U.S. critical infrastructure and other sensitive networks. The operation follows the January 2024 Volt Typhoon botnet takedown and last September's Flax Typhoon disruption, the third major court-authorized action against PRC-state hacking infrastructure in 18 months. The pace suggests infrastructure disruption has moved from exceptional remedy to standard operating procedure.

The Justice Department and FBI executed court-authorized domain seizures to deny malicious cyber actors access to QScan and QTRouter, two complementary hacking platforms used to target U.S. critical infrastructure and other sensitive networks. The DOJ attributed the platforms to Chinese state-sponsored hackers. The operation disrupted active attack infrastructure by severing adversarial control over the domains through which the platforms operated.
The QScan/QTRouter operation is the third major court-authorized disruption of PRC state-sponsored hacking infrastructure since January 2024. In that first operation, the FBI removed KV Botnet malware from hundreds of end-of-life Cisco and NetGear SOHO routers that Volt Typhoon had hijacked to conceal attacks on critical infrastructure. In September 2024, a second operation dismantled a Flax Typhoon botnet spanning more than 200,000 consumer devices (routers, IP cameras, DVRs, and NAS devices) controlled by Beijing-based Integrity Technology Group. During that disruption, PRC-linked actors attempted a DDoS attack against the FBI's remediation infrastructure; it failed.
What makes the sequence significant isn't just the frequency. Each operation has targeted a different PRC group, a different attack layer, and a different set of compromised devices: Volt Typhoon's SOHO routers, Flax Typhoon's consumer-device botnet, and now the QScan/QTRouter platform pair. The DOJ isn't swatting the same mosquito three times. It's working through a taxonomy of Chinese state-sponsored infrastructure.
For critical infrastructure defenders, the operational pattern matters because the February 2024 joint CISA-NSA-FBI advisory assessed that PRC state-sponsored actors are "seeking to pre-position themselves on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict." The advisory identified compromises across communications, energy, transportation, and water and wastewater sectors. Platform disruption buys time, but it doesn't eliminate the pre-positioning already achieved.
Published ·Deep Fathom