Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, le-action, nation-state, china] ยท confidence: high ยท affected_sectors: [government, technology, healthcare, energy, finance, defence] ยท au_impact: true

FBI and DOJ Take Down QScan and QTRouter, the Chinese Espionage Proxy Network Behind QTFY

The Department of Justice announced the takedown of QScan (an IoT-scanning and auto-infecting platform) and QTRouter (an obfuscation proxy network) run by China-based Nanjing Xinjiuwei Network Technology and used primarily by China's Ministry of State Security and the People's Liberation Army. The state-backed QTFY group has since 2018 breached the Federal Reserve, Department of Energy, DOJ, US Senate, NASA and a wide range of hospitals, telecoms, power and defence firms, exploiting compromised devices in more than 130 countries to mask the origin of its operations.

Attribute Detail
Date 2026-08-26
Actor QTFY (China, MSS / PLA-linked); operator Nanjing Xinjiuwei
Tools QScan (IoT worm), QTRouter (obfuscation proxy network)
Targets US federal agencies, hospitals, telecoms, power, defence, finance
Source The Record / DOJ โ€” Tier 2/4 High

The takedown โ€” which made the seized, hard-coded domains inoperable โ€” strips a layer of proxy anonymity on which Chinese espionage relies, following prior FBI disruptions of the Volt Typhoon and Flax Typhoon botnets and the PlugX surveillance malware.

Source