meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.
This disruption announced today is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC. In 2025, the FBI removed PlugX surveillance malware from over 4,000 U.S. computers after they had been infected by the PRC-sponsored hacker group Mustang Panda. In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which the PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government. In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of U.S. and foreign critical infrastructure. Also today, the FBI and National Security Agency published a cybersecurity advisory providing indicators-of-compromise by QTFY based on their analysis of QTFY malicious cyber activity dating back to at least 2018. In addition, Lumen Technologies’ threat intelligence group, Black Lotus Labs, published a description of QTFY’s tactics, techniques, and procedures.
The FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division investigated this hacking activity and led this disruption effort.
Note: View the affidavit here .