The Justice Department and FBI say they just pulled the plug on two China‑linked hacking platforms that were being used to probe and hide inside American networks. The agencies seized three internet domains that were hard‑coded into the malware — a move that, according to unsealed court filings, immediately crippled the tools behind broad attacks on U.S. government agencies and critical infrastructure.
What the DOJ Disrupted
Federal officials obtained court authorization to seize three domains — qtproxy.xyz, qt-proxy.org, and qt-team.com — that were built into two intrusion platforms called QScan and QTRouter. The unsealed affidavit in the Southern District of California ties the tools to a state‑sponsored group the government calls “QTFY,” which it says operates out of a China‑based firm named Nanjing Xinjiuwei. The filing alleges paying customers included the People’s Republic of China’s Ministry of State Security and the People’s Liberation Army. Named U.S. victims include the Federal Reserve, the U.S. Senate, NASA, the Department of Energy, the Justice Department itself, HHS/NIH and a long list of critical sectors such as hospitals, telecoms, power companies, financial firms and defense contractors.
How the Platforms Worked
Simple tools, big trouble
QScan acted like an automated scout and battering ram, scanning the internet for vulnerable Internet‑of‑Things devices and exploiting them at scale. Compromised devices could be pulled into QTRouter, an obfuscation network that mixed hijacked IoT gear, commercial proxy services and rented servers to make attack traffic look like it came from somewhere else. Because the three seized domains were hard‑coded for authentication and control, taking the names down made the platforms stop working — a legal and technical move that bought defenders breathing room.
Why this matters — and what we still don’t know
This operation is a win for defensive cyber ops and a signal that the U.S. is willing to take more aggressive technical steps to deny hostile state actors easy tools. But the public filings stop short of answering the big questions: what data was actually stolen, whether classified systems were touched, and how fully affected agencies have remediated their networks. The FBI and NSA issued guidance with indicators of compromise so defenders can hunt for traces, and private analysts have mapped the group’s tradecraft. Still, expect more agency briefings and congressional questions before Americans know the full damage.
Good news — but don’t pop the champagne
Attorney General Todd Blanche put it bluntly: “State‑sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” FBI Director Kash Patel said the FBI “seized adversary infrastructure and shut these platforms down.” That’s fine talk, and it deserves credit. But cutting off three domains doesn’t end the problem. China’s cyber program has been incubating tools for years, and the filings trace activity back to at least 2018. Expect more clever workarounds and more diplomacy‑free hacking. The seizure is a solid swipe in a long fight — useful, necessary, and nowhere near a knockout.

