DOJ Domain Seizures Target QTFY Botnet Alleged To Mask Chinese Hacking
The U.S. Justice Department seized three domains tied to QTFY, a group accused of using QScan and QTRouter malware to compromise IoT devices and disguise malicious traffic. The case links the infrastructure to critical-infrastructure intrusions dating to 2018 and a NASA-related FBI investigation in 2019.

The Justice Department’s seizure of three web domains has exposed infrastructure allegedly used by the China-linked QTFY hacking group to hide intrusions into government and critical-infrastructure systems, Tom’s Hardware reported, turning a years-long investigation into a public takedown of botnet infrastructure.
The Justice Department says QTFY used two malware tools, QTRouter and QScan, and claims the People’s Republic of China Ministry of State Security was among the group’s paying customers.
QScan scanned for and infected internet-of-things devices worldwide, while QTRouter used the compromised devices as an obfuscation layer for malicious traffic.
The infrastructure was tied to intrusions affecting U.S. critical infrastructure since 2018.
The case also reaches back to a 2019 FBI investigation into a NASA system intrusion connected to CVE-2019-11510, a vulnerability that was later patched.
Investigators traced activity from that NASA-related intrusion to two Gmail accounts and a phone number using China’s +86 country code.
The group allegedly rented infrastructure from commercial platforms, drawing abuse complaints from hosting provider Hostwinds to the email accounts connected to the operation.
The three seized domains — qtproxy.xyz, qt-proxy.org and qt-team.com — were registered through Namecheap and paid for through PayPal between 2022 and 2024.
The Justice Department action puts the registrar and payment trail inside the same enforcement record as the alleged malware operation, rather than treating the domains as isolated web assets.
QTFY is described as being employed by Nanjing Xinjiuwei Network Technology Company.
Chinese officials have routinely denied involvement in hacking activity in the United States, but the U.S. case treats the infected-device network as operational infrastructure for routing and disguising traffic.
For defenders, the enforcement record links commodity internet-of-things compromise, commercial hosting accounts, consumer payment rails and registrar records into one alleged intrusion-support chain.
That path gives investigators multiple points to disrupt infrastructure even when the operators and customers remain outside U.S. custody.
The seized domains now display government seizure notices, leaving the public enforcement action focused on the web infrastructure allegedly used to route and disguise malicious traffic.




















