Technology & Science

U.S. DOJ Seizes ‘QScan’ and ‘QTRouter’ Domains in China-Linked Federal Agency Hack Case

On 26 Aug 2026, U.S. authorities executed a court order to seize three internet domains that powered the QScan and QTRouter platforms, abruptly cutting off a China-sponsored intrusion network that had already breached at least six federal agencies.

By Underlines Team

Focusing Facts

  1. The FBI confiscated qtproxy.xyz, qt-proxy.org, and qt-team.com, the command-and-control hubs for QScan/QTRouter, under computer-crime and money-laundering statutes.
  2. Investigators tie the tools to Nanjing Xinjiuwei Network Technology Co., a contractor paid by China’s Ministry of State Security and staffed by former PLA operatives.
  3. Affidavits show the same infrastructure had been exploiting U.S. and South Korean hospitals, power grids, telecoms and defense firms since 2018.

Context

Domain-seizure takedowns echo the 2014 FBI ‘GameOver Zeus’ raid and the 2021 Microsoft disruption of Hafnium’s Exchange servers, but this episode sits in a lineage that began with 1999’s ‘Moonlight Maze’—state-backed digital espionage probing U.S. agencies. The shift from uniformed PLA Unit 61398 (exposed in 2013) to quasi-private contractors mirrors Cold-War-era use of front companies like Soviet Vneštorg to mask intelligence work, underscoring how great powers now outsource cyber offense. Long term, the event illustrates the entanglement of civilian critical infrastructure in geopolitical rivalry: domain seizures are temporary, but the underlying talent pool, attack surface, and incentive structure persist. If Sino-U.S. relations stay adversarial, these episodic clamp-downs may resemble early spy-plane shoot-downs—each a signal without fundamentally altering the trajectory toward a permanently contested digital commons that could define power projection well into the 22nd century.

Perspectives

U.S. mainstream and business-focused outlets

Yahoo/Reuters, CNBC, AOLPresent the Justice Department takedown as clear evidence that Beijing-backed hackers threaten critical U.S. infrastructure and hail the domain seizure as a notable American counter-punch. Stories lean heavily on DOJ court filings while offering little more than the standard Chinese ‘routine denial,’ so readers mainly get Washington’s narrative with limited scrutiny or technical detail about the alleged hacks.

Indian and other non-U.S. national outlets

Economic Times, Mint, TimesNow, The Whistler NigeriaFrame the U.S. disruption as further proof of China’s aggressive, globe-spanning cyber operations that could endanger governments and essential services well beyond America. These pieces echo Reuters copy but insert their own regional anxieties about Beijing, reinforcing pre-existing geopolitical rivalry and offering minimal independent verification or any Chinese viewpoint.

Like what you're reading?

Create a free account to read 5 articles every week. No credit card required.

Share

Related Stories