logo

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

ID: 807c2fe5-8f51-592b-832b-918c322c4200

STIX ID: report--807c2fe5-8f51-592b-832b-918c322c4200

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Pierluigi Paganini

...
...

The U.S. Department of Justice and FBI seized two China-linked platforms, QScan and QTRouter, operated by a group called QTFY (via Nanjing Xinjiuwei) that scanned for and automatically infected thousands of IoT devices and used them—alongside commercial proxies and leased VPS—to route malicious traffic and obfuscate state-origin intrusions against U.S. critical infrastructure and government entities; the seizures disrupted the malware by taking control of domains hard-coded for authentication and command-and-control. The report details exploited products (Fortinet, Citrix, Exchange, F5, Log4j, Confluence, etc.), use of web shells/RATs/stolen credentials, and frames the operation as an industrialized “quartermaster” service, concluding with defensive guidance: inventory, patching, remove unsupported devices, and monitor outbound proxy traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.