incident-responsetrade-pressNewsThe Broadside1 min read

DOJ Seizes QScan, QTRouter Tools Used to Breach Fed, Senate, NASA

The domain seizures knocked both platforms offline, but Nanjing Xinjiuwei is still operating, and the Senate was breached as recently as this year.


TL;DR

The Justice Department and FBI seized domains hard-coded into QScan and QTRouter, disabling both Chinese state-sponsored hacking platforms. The tools, built by Nanjing Xinjiuwei Network Technology and used by China's MSS and PLA, enabled the QTFY group to breach the Federal Reserve, DOE, DOJ, U.S. Senate, NASA, defense contractors, and hospitals since 2018; the Senate was hit this year. The domain seizures were surgical and effective, but the company behind the tools hasn't been touched, and QTFY exploited devices across more than 130 countries.

The FBI and DOJ seized domains hard-coded into QScan and QTRouter on Wednesday, rendering both hacking platforms inoperable in a single stroke. QScan automated the discovery and infection of vulnerable IoT devices, while QTRouter routed attack traffic through those compromised endpoints to conceal the true origin. The platforms were built and sold by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose primary customers, according to the DOJ affidavit, are China's Ministry of State Security and the People's Liberation Army.

The victim list is staggering. Since 2018, the QTFY group used these tools against the Federal Reserve, DOE, the DOJ itself, the U.S. Senate, NASA, HHS, NIH, hospitals, telecoms, power companies, financial institutions, and defense contractors.

The Senate was breached as recently as this year, though the affidavit doesn't specify which senators or committees were targeted. One of the earliest incidents investigators traced was a 2019 attempt to exploit a Pulse Secure VPN vulnerability at NASA; the IP addresses led back to locations and email addresses in China.

This isn't the first such disruption. In January 2024, the DOJ disrupted the KV Botnet, a network of hundreds of end-of-life SOHO routers hijacked by Volt Typhoon to conceal attacks on critical infrastructure. Later that year, the FBI removed PlugX surveillance malware from thousands of U.S. computers and disrupted additional botnets tied to Volt Typhoon and Flax Typhoon. The playbook is consistent: domain seizures and court-authorized malware removal are effective but temporary. Nanjing Xinjiuwei remains operational, and QTFY exploited devices in more than 130 countries. Domain seizures don't shutter the company; they raise the cost of doing business.

For practitioners at defense contractors, federal agencies, and critical infrastructure operators, the immediate step is familiar: inventory your internet-facing IoT devices and end-of-life routers. If they're not patched, they're someone else's infrastructure.


Published ·Deep Fathom