U.S. Government Seizes Chinese Hacking Platforms Targeting Critical Infrastructure

U.S. Government Seizes Chinese Hacking Platforms Targeting Critical Infrastructure

First seen 26 Aug 2026, 15:55 UTC JusticeCnbcwww.lumen.com 62.7

Article Content

Browse articles
ThreatCluster

On August 26, 2026, the U.S. Justice Department and FBI announced the seizure of domains associated with two hacking platforms, QScan and QTRouter, used by the Chinese state-sponsored hacking group QTFY. These platforms targeted U.S. critical infrastructure, including agencies such as NASA, the Federal Reserve, and the Department of Justice. QScan was designed to scan and infect IoT devices globally, while QTRouter managed the infected devices within a botnet. The seizure aims to disrupt the operations of PRC-linked cyber actors and protect national security. The DOJ emphasized its commitment to countering state-sponsored cyber threats. Court documents revealed that QTFY provided hacking services to entities like the PRC's Ministry of State Security. The current status is that the platforms have been shut down, denying access to the malicious actors.

Key Points: • The DOJ and FBI seized domains for QScan and QTRouter, used by Chinese hackers. • Victims include NASA, the Federal Reserve, and multiple federal agencies. • The seizure aims to disrupt a botnet targeting U.S. critical infrastructure.

Timeline

2026-08-26
U.S. authorities announce domain seizures
The DOJ and FBI seized domains for QScan and QTRouter, disrupting a Chinese state-sponsored hacking operation targeting critical infrastructure.
Justice
2026-08-26
Victims identified in court documents
Court documents revealed that the hacking platforms targeted agencies including NASA, the Federal Reserve, and the Department of Justice.
Cnbc