The U.S. Department of Justice, together with the Federal Bureau of Investigation, has carried out a large-scale operation to seize domains belonging to Chinese state-sponsored hackers. This concerns the QScan and QTRouter platforms, which, according to my information, were used to conduct cyberattacks on critical U.S. infrastructure facilities.

Scale of the threat: from space to the financial system

According to court documents, behind these tools is the QTFY group, affiliated with Nanjing Xinjiuwei Network Technology. Of particular concern is the fact that the clients were China's Ministry of State Security and the People's Liberation Army. Among the victims were NASA, the Federal Reserve System, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

Attack mechanics: how the QScan and QTRouter tandem worked

The operating principle was well-honed. QScan scanned the internet for vulnerable devices in the IoT sector, then automatically infected them. Each compromised device became part of the QTRouter network. This allowed the attackers to mask their tracks: the attacks appeared to originate from different countries rather than from China.

Key point: the seized domains were hardcoded directly into the code of both tools. Communication and access verification went through them, so after the domains were blocked, QScan and QTRouter completely lost functionality. This was a targeted and effective takedown.

Attorney General Todd Blanche emphasized that the operation is part of a strategy to suppress reckless attacks supported by the Chinese government. The FBI already has a successful track record of such actions: in 2025, the PlugX virus was neutralized on more than 4,000 computers, in 2024 — the Flax Typhoon botnet, and in 2023 — the Volt Typhoon infrastructure.

Notably, the number of such incidents is growing. Analysts at TeamT5 from Taiwan reported this week that Chinese groups have doubled the number of attacks by delegating routine tasks to artificial intelligence models. The case is being handled by prosecutors from the Southern District of California, and the question now is whether they are ready to bring formal charges, which would signal a shift from defensive measures to full-scale legal prosecution.

My view: This operation is not just another episode of cyberwarfare. It demonstrates that the U.S. is moving from passive defense to actively dismantling adversary infrastructure. However, the use of AI by hackers is a troubling trend: the automation of attacks makes them cheaper and larger in scale, and in the coming years we will likely see a new arms race in cyberspace.