FBI, DOJ Disrupt China QTFY Cyber Espionage Platform
DOJ announced August 26 disruption of QScan and QTRouter platforms operated by China's QTFY group to conduct reconnaissance and proxy operations against US critical infrastructure.

Confirmed. The U.S. Department of Justice announced on August 26 that the FBI has disrupted two hacking platforms — QScan and QTRouter — operated by a Chinese state-sponsored threat group designated QTFY.
What was disrupted
QScan and QTRouter functioned as operational infrastructure: reconnaissance, proxy management, and routing for Chinese cyber espionage activities. BleepingComputer describes the operation as a technical “quartermaster” — a behind-the-scenes logistics platform that supported multiple Chinese espionage campaigns against U.S. organizations.
Targets confirmed: U.S. critical infrastructure and other sensitive networks.
Attribution
DOJ attributes QTFY’s operations to Nanjing Xinjiuwei Network Technology Company (南京钺载维网络科技有限公司), a Chinese firm. Confidence on the corporate attribution: DOJ-stated, public indictment-level sourcing. Confidence on the broader Chinese state-sponsorship claim: attributed by the U.S. government; treat as high-confidence, not independently verified by 0dayNews.
What disruption means here
Infrastructure takedown, not arrest. Disruption operations of this type sever the operational plumbing — the proxy relays, the scanning infrastructure, the routing nodes — without necessarily eliminating the threat actors themselves. The platforms named in this action are offline. Replacement infrastructure is a realistic next step for a state-sponsored group with this level of resourcing.
Prior context
This action follows a sustained pattern of U.S. government responses to Chinese espionage infrastructure. Earlier this month, Treasury sanctioned IRGC-linked hackers targeting ICS environments — a separate attribution and actor set, but the same pattern of state-sponsored targeting of U.S. critical infrastructure. In August 2026, NSA and FBI warned of AI-powered attacks on Siemens PLCs attributed to a related cluster.
For organizations in critical infrastructure sectors: takedowns remove specific infrastructure, not the targeting intent. If you were a QTFY target, assume follow-on activity from reconstituted infrastructure remains possible. Review network logs from the period QScan and QTRouter were active.
Full DOJ announcement details via The Hacker News and BleepingComputer.
Found this useful? Share it.


