FBI Dismantles Global Hacker Botnet of Infected Routers and Cameras Targeting NASA, Fed, and US Senate

The US Department of Justice and the FBI announced the takedown of infrastructure belonging to Chinese hacking group QTFY. Law enforcement and intelligence agencies blocked the command platforms QScan and QTRouter, which over eight years leveraged infected routers, IP cameras, and IoT devices across more than 130 countries to launch attacks on US government agencies and critical infrastructure facilities.
US authorities named NASA, the Federal Reserve, the Department of Justice, the Department of Energy, and the US Senate among the hackers’ targets.
Architecture of the Hidden QScan and QTRouter Network
According to an official statement from the US Department of Justice, the group built a complex proxy botnet to disguise its attacks:
- QScan module: automatically scanned the internet for routers and cameras with zero-day vulnerabilities (zero-day) or outdated software;
- QTRouter network: combined compromised consumer devices with rented virtual servers, turning them into chains of anonymous proxy nodes.
Using home networking equipment allowed the group to conceal state-sponsored cyber operations: agency defense systems registered incoming traffic as legitimate requests from local internet service providers in the same cities where the targeted organizations were located.
Attack Targets and Connections to State Entities
According to Reuters, US investigators believe Chinese company Nanjing Xinjiuwei Network Technology Company was behind the development of the tools, selling hacking services to China’s Ministry of State Security and the People’s Liberation Army.
Court documents state that intrusion attempts into US Senate networks were made in 2026. Authorities emphasize that the disclosed data includes both successful instances of data theft and repelled attacks; for example, a 2019 intrusion into NASA’s infrastructure failed due to a security patch installed in advance.
Domain Seizure Operation
According to Wired, taking down the network was made possible by a court warrant to seize three key control domains hardcoded into the software of QScan and QTRouter. Seizing control of these nodes rendered the platforms operational.
Authorities remind users that outdated network hardware lacking security updates remains a primary target for botnet creation, recommending regular firmware updates for home routers and closing external remote management ports.