In a major law-enforcement move, the US government announced it disrupted a Chinese hacking platform used by state-aligned actors targeting military and critical infrastructure. The announcement, backed by statements from the Justice Department and technical details published by the FBI, centers on a threat group known as QTFY and the tools it used to find vulnerable devices, compromise them, and hide malicious activity.
This operation is a reminder that attackers often rely on repeatable services—scanning, exploitation, and evasion—rather than starting from scratch each time. When defenders disrupt the infrastructure that supports those services, the impact can cascade across many victims and industries.
What the US disrupted
According to the Justice Department, the disruption effort targeted a group described as state-sponsored: QTFY. The group is said to have operated through a company associated with Nanjing Xinjiuwei Network Technology.
Authorities allege that QTFY has offered hacking services since 2018, providing capabilities that enabled attacks against a wide range of critical systems in the United States. The disruption focused on two main services tied to that platform.
How the QScan and QTRouter services worked
The US action targeted two offerings attributed to QTFY: QScan and QTRouter. Both components were designed to work together as part of an operational pipeline.
QScan: scanning for vulnerable IoT devices
QScan is described as a scanning platform that searches the internet for weaknesses—particularly vulnerable IoT devices. The goal is to identify devices that can be compromised.
Once such devices are found, the compromised assets can be directed into the next stage of the operation.
QTRouter: building a botnet and hiding activity
QTRouter is characterized as an obfuscation network used for evasion. After devices are pulled into the botnet, threat actors can abuse those systems to conceal their malicious actions and reduce the chances of detection.
In other words, QScan helps locate targets; QTRouter helps attackers blend in and operate longer without triggering alarms.
Why court-authorized domain seizures mattered
A key part of the disruption involved authorities identifying and seizing domains associated with the QScan and QTRouter services. The Justice Department explained that these seized domains were hard-coded into both malware components and used for essential functions such as communication and authentication.
Because the domains were necessary for the tools to operate, the court-authorized seizures made QScan and QTRouter inoperable, effectively breaking the platform’s operational link.
This approach differs from stopping a single intrusion. Instead, it aims to disable the reusable infrastructure that supports ongoing attacks.
QTFY’s wider attack activity
The FBI’s technical advisory adds that QTFY worked beyond a single toolset. Authorities describe QTFY as developing malicious tools, exchanging malware and exploits, and maintaining botnets to carry out its campaigns.
The advisory also lists sectors that were targeted. These include the defense industrial base, local government, telecoms, and higher education.
That variety matters: attackers who can exploit different environments and operational needs can scale their impact across both government and private organizations.
Victims and attempted intrusions: a mixed outcome
Not every effort attributed to QTFY succeeded. The FBI reported that some hacking attempts against sensitive networks were unsuccessful. Named examples in the advisory include attacks aimed at the Department of Energy, election systems, Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company.
At the same time, other attempts appeared to achieve at least partial success. The advisory cites activity against NASA, the Justice Department, the Federal Reserve, additional Department of Energy targets, state governments, a major retailer, a telecoms company, defense contractors, universities, and financial institutions.
For defenders, this “mixed outcome” pattern is common in real-world threat operations: even when some operations fail, others can still deliver valuable access or disruption.
Vulnerabilities exploited across many vendors
Another important detail in the advisory is the range of products tied to observed exploitation. QTFY actors were reported to exploit vulnerabilities in offerings from multiple well-known security and software vendors.
The FBI specifically mentioned products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure.
This breadth suggests the group was not constrained to one technology stack. Instead, it appears to have sought out weaknesses wherever they existed, whether in enterprise applications, network infrastructure, or remote access systems.
Tools, marketplace links, and community participation
The advisory also describes how QTFY operates within a broader ecosystem. The FBI noted that QTFY actors are active in exploit development communities, freelance networks connected to the People’s Republic of China, and malicious cyber contracting and subcontracting marketplaces.
In addition, the FBI stated that QTFY participates in offensive events related to network attack and defense involving Chinese critical infrastructure.
Finally, the agency pointed out business relationships between the company behind QTFY and entities tied to cyberespionage activity, including the Salt Typhoon group, the i-Soon intrusion firm, and others.
What this means for organizations
When a Chinese hacking platform is disrupted, the immediate effect is disruption of one set of capabilities. But the longer-term message is about prevention and resilience: organizations should assume that similar scanning, exploitation, and evasion workflows can resurface through other infrastructure or toolsets.
Practical steps for defenders often include focusing on exposed systems (especially internet-facing IoT), maintaining patch discipline for relevant products, and monitoring outbound communications that match typical botnet behavior patterns.
Because QScan is described as scanning for vulnerable IoT devices, the case also highlights the importance of inventorying devices and enforcing secure configurations—areas where many environments still have gaps.
Conclusion
The US government’s disruption of the Chinese hacking platform linked to QTFY targeted core services—QScan for finding vulnerable devices and QTRouter for obfuscating malicious activity. By seizing domains hard-coded into those tools, authorities made the platform’s services inoperable, according to the Justice Department.
For organizations, the bigger takeaway is that threat actors commonly rely on modular infrastructure. When defenders disrupt that infrastructure, they can reduce the attackers’ ability to scale campaigns. At the same time, the breadth of reported targets and exploited products underscores the need for continuous hardening, patching, and monitoring across critical systems.
