DoJ disrupts QTFY QScan and QTRouter infrastructure
Law Enforcement
Summary
Hide ▲
Show ▼
The U.S. Department of Justice disrupted QScan and QTRouter, cutting off a cybercrime infrastructure used by QTFY to target U.S. critical infrastructure and other sensitive networks. The court-authorized action seized hard-coded domains embedded in both platforms, forcing them offline.
Related Happenings
QTFY long-running campaign against U.S. critical infrastructure
Campaign
H score35
First: 26.08.2026 19:42
Last: 26.08.2026 19:42
Sources 1
How related:
"Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States,"
About this happening:
The QTFY campaign has been mapped as a long-running operation against U.S. critical infrastructure and sensitive networks, with activity dating to 2018 and attacks rep...
QTFY long-running campaign against U.S. critical infrastructure
CampaignHow related: "Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States,"
About this happening: The QTFY campaign has been mapped as a long-running operation against U.S. critical infrastructure and sensitive networks, with activity dating to 2018 and attacks rep...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementAbout this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementAbout this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
Campaign
H score45
First: 07.04.2026 18:51
Last: 07.04.2026 18:51
Sources 1
About this happening:
A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
CampaignAbout this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
Timeline
-
26.08.2026 19:42 2 articles · 2h ago
DoJ disrupts QScan and QTRouter
Legal Policy Action UpdateThe U.S. Department of Justice disrupted QScan and QTRouter, two hacking platforms used by QTFY to target U.S. critical infrastructure and other sensitive networks, and seized hard-coded domains that caused both platforms to cease operations.
Show sources
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations — thehackernews.com — 26.08.2026 19:42
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations — thehackernews.com — 26.08.2026 19:42
-
26.08.2026 19:42 1 articles · 2h ago
FBI details QTFY's IoT-infecting proxy network
Technical Analysis UpdateThe FBI described QScan as a tool that scans and automatically infects IoT devices worldwide, adds them to QTRouter, and uses custom OpenWrt routers, commercial proxy services, leased VPSs, and Clash-based chaining to conceal intrusion origins. The same reporting linked QTFY to victims including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate.
Show sources
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations — thehackernews.com — 26.08.2026 19:42