Circuit Wire — a daily news update from the Circuit.
The Justice Department and FBI seized three internet domains on Wednesday to shut down two hacking platforms, QScan and QTRouter, that a China-based group known as QTFY used to breach US critical infrastructure since 2018. Court documents unsealed in the Southern District of California name victims including NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services, along with the National Institutes of Health.
Prosecutors said QTFY operated out of a private front company, Nanjing Xinjiuwei Network Technology Company, and sold hacking services to buyers that included China's Ministry of State Security and the People's Liberation Army. The group's roster included former members of China's military, according to court records. Its two tools worked together: QScan scanned and automatically infected thousands of internet-connected devices worldwide, and QTRouter folded those devices into a network that hid the origin of the attacks so they appeared to come from outside China.
QScan was built for scale. It carried more than 200 ready-made exploits, and on a single day in 2024 it processed over two million scanning and exploit tasks, an FBI agent said in the affidavit. In September 2024, the group used Ivanti zero-day flaws to break into three Department of Energy national laboratories, an NIH network and a US-based security device maker. The group also tried, without success, to reach a US Senate network in March and a US election system in June, CyberScoop reported.
"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," Attorney General Todd Blanche said. FBI Director Kash Patel described the action as the disruption of a global botnet used to hide the origin of Chinese state-sponsored attacks.
The takedown is the latest in a run of similar operations. In 2025, the FBI removed PlugX malware from more than 4,000 US computers tied to the group Mustang Panda. In 2024 it disabled a botnet run by Flax Typhoon, and in 2023 it disrupted infrastructure used by Volt Typhoon to hide activity inside US critical networks. The FBI and National Security Agency published a joint advisory on Wednesday listing QTFY indicators of compromise dating back to at least 2018.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

