The US Department of Justice (DOJ) and FBI on Wednesday, August 26, 2026, announced court-authorized domain seizures targeting two complementary hacking platforms, QScan and QTRouter, that prosecutors say were used by a China-linked group to attack US critical infrastructure and other sensitive networks.
According to court documents unsealed in the Southern District of California, the platforms were created and operated by a group known as QTFY, which prosecutors describe as being associated with China-based Nanjing Xinjiuwei Network Technology Company.
Among the named victims of the group’s intrusion activity, the DOJ said, are the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.
What QTFY Is, According to Prosecutors
Court filings describe QTFY as a “hackers for hire” operation that allegedly sold computer-hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. Prosecutors say the group included former PLA members and that Nanjing Xinjiuwei received payments from the MSS, which the government says supports its assessment that the company conducted malicious cyber activity on behalf of the Chinese government.
The FBI shared that it has been investigating QTFY since at least 2019, and that the group has been active since around May 2018.
These are government allegations and attributions contained in court filings, rather than findings against an individual defendant. China has previously denied US allegations of state-sponsored hacking.
How QScan and QTRouter Worked
The two platforms allegedly had distinct, complementary jobs.
QScan is described by prosecutors as a scanning-and-exploitation tool that automatically searches the internet for vulnerable internet-of-things (IoT) devices and compromises them at scale. According to the affidavit, QScan processed more than two million scanning and exploitation tasks on a single day in 2024. Compromised devices were then folded into QTRouter, an “obfuscation network” built from hijacked IoT devices, commercial proxy services, and leased virtual private servers.
That obfuscation layer was reportedly designed to make malicious activity harder to trace. By routing traffic through compromised devices belonging to legitimate users, including devices on networks close to a target, QTRouter allegedly allowed operators to make attacks appear to originate from ordinary computers outside China.
The FBI seized three domains, reported as qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com, that were hard-coded into the malware for communication and authentication, according to the court documents. The seizures rendered the two platforms inoperable.
The seized domains now display a law-enforcement banner. Court filings also cite probable cause that the domains were used in a money-laundering conspiracy. That allegation has not been established as a criminal conviction.
Alongside the seizures, the FBI and National Security Agency published a joint cybersecurity advisory listing QTFY indicators of compromise. Lumen Technologies’ Black Lotus Labs, which tracked the infrastructure and assisted the operation, also published a technical analysis of the group’s methods.
Part of a Broader Campaign Against China-Linked Hacking
The action is the latest in a series of US technical operations against China-linked cyber activity.
In 2024, the FBI and its partners disrupted a botnet of more than 200,000 compromised IoT devices linked to China-sponsored hackers known as Flax Typhoon. Earlier, in January 2024, the FBI disrupted a Volt Typhoon botnet made up of hundreds of compromised routers that was used to conceal activity targeting US critical infrastructure.
The operations show the extent to which US authorities have increasingly used domain seizures, malware removal, and infrastructure disruption alongside traditional investigations to counter suspected China-linked cyber activity.
Why It Matters for the Crypto Industry
This operation did not involve cryptocurrency. The named targets were government and research networks, and the seized tools were designed for scanning, exploitation, and traffic obfuscation rather than digital-asset theft.
The relevance to crypto is that exchanges, custodians, blockchain infrastructure providers, and other digital-asset businesses also operate internet-facing systems that can be targeted by sophisticated attackers.
The QTFY operation highlights two security issues that can extend across industries: the exploitation of vulnerable internet-connected devices and the use of compromised infrastructure to make malicious traffic harder to attribute. Those techniques are distinct from the crypto-focused activity associated with North Korean groups such as Lazarus, which have been linked by US authorities and other investigators to digital-asset theft.
But the presence of the Federal Reserve among the named victims also illustrates why financial infrastructure remains a target for sophisticated cyber operations.
The Crypto Times is reporting the government’s allegations and enforcement action; nothing in the available documents indicates that a cryptocurrency exchange or blockchain platform was compromised in this specific operation.
Right of Reply: The Crypto Times could not identify publicly available contact details for all entities named in the US government’s filings before publication.
Also Read: Saitama CEO Loses UK Challenge to Extradition Over US Fraud Charges
