2026-08-28 · view entry permalink →
DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA — NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named as victims since 2018, with European infrastructure among Lumen's own profiled targets
DOJ and the FBI announced court-authorized domain seizures on 2026-08-26 against "QScan" and "QTRouter", two complementary hacking platforms unsealed court documents attribute to "QTFY" (aka QT/QTCYBER), a PRC state-sponsored contractor run by Nanjing Xinjiuwei Network Technology Company that received payments from China's Ministry of State Security. BleepingComputer's reporting of the unsealed court documents adds a staffing detail neither DOJ's nor Lumen's own material states directly: "Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing" (BleepingComputer, 2026-08-26). QScan is a three-stage reconnaissance pipeline — a Celery/RabbitMQ task broker, a distributed scanner fleet that rotates across /24 subnet blocks on a 30-day cycle to dodge threshold detection, and a Redis results backend — that fingerprints IoT devices, OS kernels and exposed management interfaces worldwide. QTRouter, which Lumen's Black Lotus Labs calls a "quartermaster" enablement layer after tracking the same infrastructure for over a year under the names "Fast Labyrinth" and "QTProxy", turns QScan-compromised IoT devices, leased VPS instances, and — most distinctively — bulk-purchased subscriptions to the Chinese "Airport" (机场) commercial GFW-circumvention proxy service into an obfuscation-as-a-service network: because the seized domains were hard-coded into both platforms for communication and authentication, "the court-authorized seizures made QScan and QTRouter inoperable" (U.S. Department of Justice, 2026-08-26).
Named victims since at least 2018 include NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, NIH, and the U.S. Senate — "among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate" (U.S. Department of Justice, 2026-08-26). Lumen's independent telemetry additionally shows sustained QScan/Fast-Labyrinth targeting of research universities, defense-supplier perimeters, and — explicitly — European infrastructure and judicial nodes worldwide, describing the reconnaissance purpose plainly: "systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously" (Lumen Technologies — Black Lotus Labs, 2026-08-26). Lumen found direct crossover between administrative check-in sessions from Nanjing (China Telecom/Unicom IP space) and the co-opted commercial proxy nodes — evidence the operators actively tested and calibrated the leased infrastructure before leasing it to downstream customers.
The takedown follows the same court-authorized disruption playbook DOJ/FBI used against Flax Typhoon (2024) and Volt Typhoon (2023) ORB networks. Lumen cautions that because the proxy layer rides on dynamically-rotating legitimate commercial subscriptions rather than a static botnet, blocklisting alone will not be durable, and recommends the CISA/NCSC ORB-mitigation guidance. For this constituency, the relevant read is not the US federal victim list but the infrastructure model itself: a hacking-as-a-service anonymisation layer leased to multiple PRC state customers, explicitly profiled by its own independent tracker as reaching European infrastructure and judicial systems, is the same class of ORB (operational relay box) infrastructure prior Volt Typhoon and Flax Typhoon disruptions have shown reaching European routers and critical-infrastructure networks.
actions[] is empty: this is a completed law-enforcement disruption rather than a live exposure this constituency can patch, hunt or block against directly — the transferable lesson is awareness of the ORB infrastructure class and CISA/NCSC's published ORB-mitigation guidance, which the body above already carries.
Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.
Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.
Systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously.
Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing