The Department of Justice has seized Web domains in order to block the access of PRC-backed cyberhackers to “two complementary hacking platforms known as ‘QScan’ and ‘QTRouter,’ used to target U.S. critical infrastructure and other sensitive networks” (Department of Justice, August 26, 2026).
“Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” the DOJ press release says.
QTFY
The group of hackers is known as “QTFY,” DOJ says. Among the victims of its intrusions: “the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.”
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” says Attorney General Todd Blanche.
FBI Director Kash Patel says that the government disrupted “a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. These tools were used by PRC cyber actors to hide the origin of their attacks…. Today’s action is just the latest technical operation against PRC-sponsored hacking….”
I can’t quite tell from the press release whether the U.S. is doing well against PRC-backed cyberhackers because we keep detecting and combating them or doing poorly because they keep attacking and intruding. Did the QTFY cyberattacks succeed in compromising any of the long list of U.S. agencies and institutions targeted?
CNBC notes that the DOJ “did not detail the damage to the agencies or other targets from the computer intrusions.”
IoT
It seems as if some compromising of systems must have occurred if QTFY has been operating for any length of time.
“QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. These computer hacking services include QScan and QTRouter, which work in conjunction. QScan scans and automatically infects thousands of ‘internet-of-things’ (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers.”
It also seems that it’s not just the many listed parts of the U.S. government that were likely compromised.
Federal Reserve
Speaking of the Federal Reserve, last month the DOJ announced that a former advisor to the Fed’s Board of Governors, John Harold Rogers, had been sentenced to 38 months in prison for “making false statements to federal investigators about sharing restricted Federal Reserve information with Chinese intelligence operatives.”
That’s all the jury was willing to find Rogers guilty of back in February, even though, says one government official involved in the case, Rogers was concealing the fact that he “shared restricted non-public Federal Reserve information with intelligence agents working for China.”
An FBI agent says that Rogers “repeatedly violated Federal Reserve information security policies by taking sensitive, nonpublic information and sending it to himself, while he was in China, and to others affiliated with the Chinese Communist Party.”
Rogers understood that Hummin Lee, the intelligence operative with whom Rogers began a relationship in 2017, “was writing reports for the Chinese government using the information he provided, and knew China could use advance knowledge of Federal Reserve interest rate decisions to generate enormous profits trading its roughly $1.5 trillion in U.S. Treasury securities.”
You can lie about what you are doing only if you know that you are doing it. If the jury determined that Rogers was guilty about lying about being a spy for the Chinese Communist Party, why didn’t it also find him guilty of being a spy for the CCP?
Giving the party-state an easy way to make oodles of money is tantamount to delivering pallets of cash, not the best way to weaken a hostile government. Maybe the CCP hacked the jury.