US authorities disrupted QScan and QTRouter, two platforms allegedly operated by the China-linked QTFY group to scan for, compromise, and proxy traffic through internet-connected devices. The Department of Justice and FBI seized supporting domains and linked the operation to Nanjing Xinjiuwei Network Technology, whose alleged customers included China’s Ministry of State Security and the People’s Liberation Army. China denied involvement.
QScan was reportedly used for mass vulnerability scanning and automated exploitation, while QTRouter turned compromised devices into an obfuscation network for attacker traffic. A joint FBI, NSA, and Cyber National Mission Force advisory reported that QScan handled more than two million scanning and penetration-testing tasks in a single day; alleged targets included government agencies, defense contractors, energy, telecommunications, finance, and universities. Organizations should patch exposed edge devices, segment critical systems, and hunt for published indicators, as compromised devices and stolen credentials may still provide residual access after the seizures.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
A joint FBI, NSA, and Cyber National Mission Force advisory reported that QScan processed more than two million scanning and penetration-testing tasks in a single day in 2024.
China denied involvement in the alleged campaign and accused the United States of using cybersecurity concerns to discredit Chinese companies.
US officials alleged that QTFY operated through Nanjing Xinjiuwei Network Technology and that the company's customers included China’s Ministry of State Security and the People’s Liberation Army.
US authorities, including the Department of Justice and FBI, disrupted the QScan and QTRouter platforms by seizing supporting domains. Officials alleged the platforms were used by the Chinese state-sponsored QTFY group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.