The US Department of Justice and FBI seized three domains on Wednesday that they say Chinese state-sponsored hackers used to run a botnet behind intrusions at several federal agencies, including:
- NASA
- The US Senate
- The Federal Reserve
- The Department of Energy
- The Department of Justice
- The Department of Health and Human Services
- The National Institutes of Health
According to the Justice Department’s announcement, the intrusions were carried out by a group it identifies as QTFY, using two purpose-built malware tools called QScan and QTRouter. The department says the People’s Republic of China’s Ministry of State Security was one of QTFY’s paying customers, and that the group operates through a company it names as the Nanjing Xinjiuwei Network Technology Company.
The three seized domains, qtproxy.xyz, qt-proxy.org and qt-team.com, now display a federal seizure notice. The unsealed affidavit traces the operation back to 2018 and describes QScan as software that scans for and automatically infects thousands of internet-of-things devices worldwide, folding each one into the QTRouter network.
How Chinese state-sponsored hackers ran the QTRouter botnet
Once a device is compromised, QTRouter turns it into what the Justice Department calls an obfuscation layer, a hop that routes attack traffic through someone’s infected home router or smart device rather than through infrastructure that traces back to the operator. That is a standard technique in state-linked intrusion sets, and it is why this action targets domains and command infrastructure rather than the individual devices doing the routing, since the FBI cannot practically clean every infected router.
Tom’s Hardware reports that the FBI’s investigation dates back to 2019, when agents examined a NASA intrusion tied to CVE-2019-11510, a Pulse Secure VPN vulnerability patched years ago. They traced the activity to two Gmail accounts and a phone number carrying China’s +86 country code, and found the group had rented infrastructure from commercial hosts, which prompted a string of abuse complaints to those Gmail addresses from hosting provider Hostwinds. The three seized domains were registered between 2022 and 2024.
Eight years between first breach and seizure
By teqpost’s arithmetic, eight years separate the first documented compromise attributed to Chinese state-sponsored hackers in 2018 from Wednesday’s seizure. That gap says as much about the mechanics of a case like this as it does about the group: the affidavit shows years spent tying anonymous Gmail accounts and rented servers to a single operation before there is enough evidence to seize even three domains. It also underlines a structural point the Justice Department is explicit about: QTFY is described as a contractor, not an arm of Chinese intelligence, whose most notable client happened to be the Ministry of State Security. The same botnet infrastructure would presumably have been available to any customer able to pay.
Seizing three domains removes QTFY’s current command infrastructure but does nothing for the IoT devices already infected and still listening for QTRouter traffic; those need patching or replacement by their owners, not law enforcement. Worth watching is whether CISA follows with an advisory naming the affected device models, and whether the seizure is followed by unsealed criminal charges against the Nanjing Xinjiuwei Network Technology Company or named individuals, something that has not happened yet.








