U.S. law enforcement has struck a preemptive blow against Chinese state-sponsored cybercrime. The Department of Justice and the FBI have seized the QScan and QTRouter domains — key elements of infrastructure used for attacks on critical targets, including NASA, the Federal Reserve, and the Senate.

Anatomy of the Chinese Cyber Threat

Behind these platforms is the QTFY group, affiliated with Nanjing Xinjiuwei Network Technology. According to court documents, QTFY provided hacking services for a fee, with its clients including China's Ministry of State Security and the People's Liberation Army. This is not about ordinary lone-wolf hackers, but about structures operating in the interests of the country's highest military and political leadership.

In addition to the space agency, the Fed, and the upper house of Congress, victims of the attacks included the Department of Energy, the Department of Justice, the Department of Health and Human Services, and the National Institutes of Health. The scale is staggering: targets included facilities ensuring financial stability, national security, and the health of American citizens.

Attack Technology: How the QScan and QTRouter Combination Worked

The mechanics were built with a high degree of sophistication. QScan scanned the Internet of Things (IoT) for vulnerable devices and automatically infected them. Each infected device was then incorporated into the QTRouter network, which connected them to commercial proxy services and rented virtual servers.

This approach allowed the attackers to mask the true origin of their operations: from the outside, it appeared that requests were coming from various countries rather than from China. This is a classic tactic for covering tracks, which significantly complicated attribution. Investigators determined that the seized domains were "hardcoded" into the code of both tools — communication and access verification flowed through them. After the domains were blocked, QScan and QTRouter completely ceased operations.

Attorney General Todd Blanche called the operation "one of the latest in a series of technical takedowns of reckless attacks supported by the Chinese government." This is not the first such action: in 2025, the FBI removed the PlugX virus from more than 4,000 computers; in 2024, it neutralized the Flax Typhoon botnet; and in 2023, it took down Volt Typhoon infrastructure.

Prosecutors from the Southern District of California are handling the case. For now, it involves the seizure of servers, but criminal charges are possible in the future.

My take: This operation demonstrates a paradigm shift in the fight against state-sponsored cyberespionage. Instead of passive defense, the U.S. is moving toward actively dismantling enemy infrastructure, setting a precedent for the entire world. However, the escalation of the cyber conflict between superpowers is an alarming signal for the global financial system: if the Fed was in the crosshairs, no institutional player, including crypto exchanges, can feel safe.