US Seizes Domains, Disrupts Chinese QTFY Botnet

US authorities seized domains tied to QScan and QTRouter, disabling the QTFY scanning platform and botnet used to target U.S. military and critical infrastructure systems.
U.S. authorities on Wednesday seized internet domains tied to two hacking tools, QScan and QTRouter, used by a group known as QTFY. The seizures rendered the malware inoperable and interrupted a campaign that targeted military systems and critical infrastructure in the United States.
The Justice Department carried out the domain seizures with court authorization and announced the action the same day the FBI published a technical advisory on the tools. QScan was built to scan the public internet for vulnerable internet-of-things devices and enroll them into the QTRouter botnet. QTRouter then routed attacker communications through those compromised devices to hide activity and evade detection.
“Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” the Justice Department said.
The FBI linked QTFY to a company called Nanjing Xinjiuwei Network Technology and said the group has operated since 2018. According to the advisory, QTFY developed offensive tools, traded malware and exploits, and maintained botnets that enabled operations for the Chinese government and other customers.
Targets identified in the FBI advisory included the defense industrial base, local governments, telecommunications firms and institutions of higher education. The agency reported some intrusion attempts did not succeed, citing efforts against the Department of Energy, election systems, the Department of Health and Human Services, the U.S. Senate, a children’s hospital, a semiconductor company and a regional power provider. Other incidents appeared to have at least partial success against organizations such as NASA, the Justice Department, the Federal Reserve, state governments, a major retailer, telecom companies, defense contractors, universities and financial firms.
Investigators observed QTFY exploiting a range of software vulnerabilities to gain access to networks. The advisory names product vendors whose flaws were used in intrusions, including BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet and Pulse Secure.
The FBI’s advisory also described business ties between the company behind QTFY and other cyber actors and firms, including connections to groups identified as Salt Typhoon and i‑Soon. The advisory noted QTFY’s activity within exploit development communities and contracting markets that provide offensive cyber capabilities.
The FBI published indicators of compromise and technical guidance for organizations to check for signs of intrusion and to remediate affected devices. The Justice Department said the domain seizures are part of an ongoing effort to disrupt infrastructure used to target U.S. critical systems.







