Find notable cyber news and cases, enriched with sources, timelines, and signals.

DoJ disrupts QTFY QScan and QTRouter infrastructure

Law Enforcement
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

The U.S. Department of Justice disrupted QScan and QTRouter, cutting off a cybercrime infrastructure used by QTFY to target U.S. critical infrastructure and other sensitive networks. The court-authorized action seized hard-coded domains embedded in both platforms, forcing them offline.

Related Happenings

QTFY long-running campaign against U.S. critical infrastructure

Campaign
H score35 First: 26.08.2026 19:42 Last: 26.08.2026 19:42 Sources 1

How related: "Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States,"

About this happening: The QTFY campaign has been mapped as a long-running operation against U.S. critical infrastructure and sensitive networks, with activity dating to 2018 and attacks rep...

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
H score33 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...

FBI seizes NetNut and Popa botnet domains

Law Enforcement
H score34 First: 02.07.2026 22:27 Last: 02.07.2026 22:27 Sources 1

About this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...

APT28 FrostArmada DNS hijacking and AitM credential theft campaign

Campaign
H score45 First: 07.04.2026 18:51 Last: 07.04.2026 18:51 Sources 1

About this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...

Timeline

  1. 26.08.2026 19:42 2 articles · 2h ago

    DoJ disrupts QScan and QTRouter

    Legal Policy Action Update

    The U.S. Department of Justice disrupted QScan and QTRouter, two hacking platforms used by QTFY to target U.S. critical infrastructure and other sensitive networks, and seized hard-coded domains that caused both platforms to cease operations.

    Show sources
  2. 26.08.2026 19:42 1 articles · 2h ago

    FBI details QTFY's IoT-infecting proxy network

    Technical Analysis Update

    The FBI described QScan as a tool that scans and automatically infects IoT devices worldwide, adds them to QTRouter, and uses custom OpenWrt routers, commercial proxy services, leased VPSs, and Clash-based chaining to conceal intrusion origins. The same reporting linked QTFY to victims including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate.

    Show sources