US Justice Department Seizes China Sponsored Hacking Platforms QScan and QTRouter Linked to Breaches at NASA Federal Reserve and Senate
Federal law enforcement authorities in the United States have taken control of critical internet infrastructure and seized key digital domains used by state sponsored Chinese cyber operatives to infiltrate high level government networks, space research centers, and financial institutions. The sweeping disruption dismantled two interconnected malicious platforms known in cybersecurity circles as QScan and QTRouter, which operated as a global botnet to breach internet connected devices and disguise the geographic origin of espionage campaigns. The covert digital offensive targeted vital civilian and military organizations, allowing foreign operatives to compromise computer systems across North America and East Asia.
Court records unsealed in federal court in San Diego revealed that the infrastructure seizures took place following an authorized warrant on Wednesday, 26 August 2026. According to investigators from the Federal Bureau of Investigation and federal prosecutors, the seized technical platforms were operated directly by a China based entity identified as Nanjing Xinjiuwei Network Technology Company. Intelligence filings state that the commercial software firm functioned as a private cyber contractor providing offensive digital tools, reconnaissance services, and network penetration software to prominent state clients, including China Ministry of State Security and the People Liberation Army.
The cyber operation successfully infiltrated or attempted to breach an extensive list of sensitive American public institutions. Court affidavits confirmed that targets included the United States Senate, the Federal Reserve, the Department of Justice, the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health. Space agency servers at NASA were also targeted in attempted network breaches, alongside 4 major commercial corporations located in the United States and South Korea. Investigators noted that the underlying digital infrastructure had been systematically utilized since at least 2018 to compromise critical infrastructure, power utilities, regional hospitals, and defense contractors.
Technical disclosures explain that the 2 seized platforms operated in close tandem to automate and conceal espionage activities. The first platform, QScan, functioned as an automated digital scanner that continuously searched the public internet for vulnerable routers, firewalls, and interconnected smart devices worldwide. Once a vulnerability was detected, the software automatically infected the hardware with malicious code, quietly enrolling the compromised hardware into an expanding network of remotely controlled computers known as a botnet.
The second platform, QTRouter, then transformed those thousands of infected civilian devices into an obfuscation relay network. Whenever intelligence operatives in China launched an intrusion against American government databases, the malicious traffic was routed through compromised hardware located in neighborhood offices or residential homes situated close to the victim organization. Because the incoming network requests appeared to originate from ordinary domestic devices rather than overseas servers, security monitoring systems struggled to detect the attacks, significantly slowing down forensic detection and attribution efforts by cybersecurity teams.
The court authorized enforcement action was directed by the FBI San Diego Field Office, working alongside the Cyber Division and federal prosecutors in the Southern District of California. United States Attorney General Todd Blanche stated that state sponsored malicious hackers preying on American critical infrastructure will be pursued and disrupted using every available legal and technical mechanism. FBI Director Kash Patel confirmed that the targeted takedown severed the core communication links of the botnet, rendering the command infrastructure inoperable and denying foreign state operatives a key tool used to shield digital espionage.
Cybersecurity analysts emphasize that the operation sheds light on the rapid expansion of private commercial contractors within modern cyber warfare. Over the past decade, state intelligence agencies have increasingly outsourced offensive technical development to specialized private software vendors. These commercial firms develop custom exploitation software, build large scale routing networks, and provide branded hacking services directly to military and intelligence units. Industry experts note that seizing domain infrastructure imposes significant financial and operational costs on these contractor ecosystems, forcing them to rebuild technical architectures from scratch.
The action represents the latest in a series of coordinated enforcement operations designed to neutralize advanced persistent threat networks operating across the Pacific. In recent years, security agencies have raised alarms over foreign cyber units seeking to embed themselves deep inside western telecommunications switches, electrical power distribution grids, and transport hubs. Defense analysts warn that such long term access can be exploited not only for intelligence gathering but also for destructive disruptive attacks during geopolitical crises.
International reaction to the seizures highlights the ongoing friction between Washington and Beijing over cyberspace governance and national sovereignty. The Chinese Embassy in Washington did not immediately issue a public response to the court filings, while official spokespersons in Beijing have historically rejected allegations of state directed cyber espionage, maintaining that China is itself a frequent victim of foreign digital intrusions. Despite these recurring diplomatic denials, American prosecutors stated that federal law enforcement will continue to target, indict, and dismantle commercial digital infrastructure used to facilitate state sponsored intrusion campaigns.
While the seizure of the primary domains successfully disables the current operational capabilities of QScan and QTRouter, cybersecurity specialists caution that the underlying threat remains highly dynamic. Malicious actors frequently attempt to register alternate server domains, shift to decentralized routing protocols, and deploy new malware variants to re-establish compromised botnets. Federal cybersecurity authorities have urged private network administrators, corporate enterprises, and government agencies to implement multi-factor authentication, apply routine security patches to edge routing devices, and review internal network traffic for indicators of unauthorized proxy activity.