Ethical Hacking News
The FBI has seized two China-linked hacking platforms, QScan and QTRouter, used to target critical infrastructure and sensitive networks. The platforms were used by a group known as QTFY, which was operated by a China-based company and offered hacking services to Chinese government agencies and the People's Liberation Army. The seizure is significant because it highlights the growing threat of state-backed hacking operations and the importance of patching known vulnerabilities quickly. The FBI notes that the disruption announced today is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC.
The FBI has disrupted a China-linked hacking group known as QTFY, which used sophisticated tools to target critical infrastructure and sensitive networks. The group used platforms QScan and QTRouter to hide cyberattacks and conceal their identities, which have now been seized by the FBI. The QTFY group offered hacking services to China's Ministry of State Security and the People's Liberation Army. The group's approach highlights the growing threat of state-backed hacking operations, which can use shared scanning tools and compromised devices to launch complex attacks. The FBI advises individuals to inventory internet-facing assets, patch known vulnerabilities, remove unsupported devices, and monitor unusual outbound proxy traffic to prevent similar attacks. The seizure of QScan and QTRouter is part of a series of court-authorized technical operations against indiscriminate hacking activities by the PRC. The QTFY group exploited multiple vulnerabilities in widely deployed products, including Fortinet SSL-VPN and Microsoft Exchange.
The U.S. Federal Bureau of Investigation (FBI) has announced a significant operation to disrupt and dismantle a China-linked hacking group that has been using sophisticated tools to target critical infrastructure and sensitive networks. The operation involves the seizure of two platforms, QScan and QTRouter, which were used by the group to hide cyberattacks and conceal their identities.
According to the FBI, the group, known as QTFY, was operated by a China-based company called Nanjing Xinjiuwei Network Technology Company. The group offered hacking services to paying clients, including China's Ministry of State Security and the People's Liberation Army. The FBI attributes the activity to QTFY, which used QScan and QTRouter to scan the internet for vulnerable devices, infect thousands of exposed Internet of Things (IoT) devices, and add them to the QTRouter network.
The QTRouter network was used to route malicious traffic through systems located outside of China, making it harder for authorities to track the origin of the attacks. The FBI seized the domains used by QScan and QTRouter, which were hard-coded into the platforms and used for core functions such as authentication and command-and-control communication.
The seizure of QScan and QTRouter is significant because it highlights the growing threat of state-backed hacking operations. The FBI notes that the group's approach shows how state-sponsored actors can use shared scanning tools, compromised devices, commercial proxy services, and rented servers to launch complex attacks without having to build every part of the attack from scratch.
The FBI also highlights the importance of inventorying internet-facing assets, patching known vulnerabilities quickly, removing unsupported devices, monitoring unusual outbound proxy traffic, and not assuming that an IP address tells you who is behind an attack. The agency notes that the disruption announced today is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC.
The QTFY group reportedly exploited both old and newly disclosed vulnerabilities in widely deployed products, including Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point gateways, CrushFTP, Ivanti appliances, and BeyondTrust Remote Support. The attack chain also included web shells, remote-access trojans, stolen or legitimate credentials, and compromised IoT devices used as nearby relay points.
The seizure of QScan and QTRouter follows earlier FBI actions against China-linked botnets. In 2025, the FBI removed PlugX malware from more than 4,000 infected U.S. computers linked to Mustang Panda. In 2024, it disrupted a botnet of hundreds of thousands of IoT devices associated with Flax Typhoon, while in 2023 it acted against a Volt Typhoon botnet used to conceal activity targeting U.S. and foreign critical infrastructure.
Related Information:
https://www.ethicalhackingnews.com/articles/FBI-Cracks-Down-on-China-Linked-Hacking-Operations-Seizes-QScan-and-QTRouter-Platforms-ehn.shtml
https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html
Published: Wed Aug 26 13:25:06 2026 by llama3.2 3B Q4_K_M