The FBI and Justice Department have disabled two platforms used by the China-linked QTFY hacking group: the QScan botnet and the QTRouter proxy network. Court-authorized domain seizures broke hard-coded connections that the platforms relied on, making both systems inoperable, according to the Justice Department.[1]
The operation matters beyond the government agencies and critical-infrastructure organizations QTFY targeted. Thousands of compromised routers, cameras, and other Internet of Things (IoT) devices served as the group’s relay layer. In other words, an ordinary device could help conceal an attack even when its owner was not the intended victim.
How QScan and QTRouter worked together
QTFY operated a two-part system. QScan searched for and exploited exposed devices. QTRouter then routed attack traffic through compromised equipment and commercial proxy services, making malicious connections look as if they originated near the target. The joint FBI, NSA, and U.S. Cyber Command advisory says the activity has affected defense, communications, government, higher education, energy, water, and other sectors since at least 2018.[2]
| Component | Role | Why it mattered |
|---|---|---|
| QScan | Scanned the internet and tested known exploits | Built a pool of compromised routers and IoT devices |
| QScan botnet | Ran tasks through infected devices | Distributed reconnaissance and intrusion activity |
| QTRouter | Chained compromised devices and proxy services | Obscured the real origin of attacks |
The scale was substantial. Investigators found more than 200 proof-of-concept exploits in the QScan database. On one day in 2024, the system handled more than two million scanning and penetration-testing tasks. The advisory also attributes a May 2024 campaign that exfiltrated data from more than 300 organizations to QScan activity.[2]
Lumen’s Black Lotus Labs independently tracked the supporting infrastructure and described QTFY as an “infrastructure quartermaster”: a service that supplied scanning, compromised devices, and proxy routes to other China-nexus operators.[4] That distinction helps explain why both targets and relay devices appear in the same investigation.
What the FBI seizure changed
The seizure removed domains hard-coded into QScan and QTRouter. The Justice Department says losing those domains rendered the platforms inoperable.[1] This is a meaningful disruption: it prevents the seized infrastructure from coordinating the compromised-device pool in its previous form.
It is not the same as remotely repairing every affected router or camera. A seizure does not install current firmware, remove unrelated malware, reverse stolen credentials, or make an unsupported device safe. That is an operational inference from what the government action changed—the command infrastructure—versus what device owners still control. Similar proxy networks can also be rebuilt if exposed equipment remains available.
The NSA therefore pairs the disruption announcement with defensive guidance, not an all-clear. It advises organizations to update software and firmware, protect operational information, isolate critical systems from edge devices, and investigate the published indicators.[3]
Who should check routers and edge devices
Network defenders should prioritize internet-facing routers, VPN appliances, cameras, and other edge or IoT systems—especially models that no longer receive security updates. QTFY’s tooling used a broad library of known exploits, so the relevant question is not whether a device carried a “QTFY” label. It is whether the device was reachable, vulnerable, unexpectedly reconfigured, or communicating through suspicious infrastructure.
Small businesses and home users face a simpler version of the same issue. A compromised router may continue providing normal internet access while proxying someone else’s traffic. Our guide to checking and securing an exposed router covers the settings that deserve attention. The recent Dysphoria router-proxy campaign shows why attackers value residential-looking IP addresses.
What organizations and device owners should do
- Install supported firmware and software. Confirm the update on the device itself; do not rely only on an asset spreadsheet.
- Remove unnecessary exposure. Disable internet-facing administration, UPnP, and unused forwarded ports unless there is a documented need.
- Separate edge and IoT equipment. Do not let a camera or router management interface provide an easy path into sensitive systems.
- Review configuration and logs. Check DNS settings, administrator accounts, scheduled tasks, unfamiliar services, and unexplained outbound connections.
- Use the official indicators carefully. The joint advisory warns that an indicator alone does not prove compromise. Validate context before blocking shared proxy or cloud infrastructure.[2]
- Replace unsupported hardware. If a vendor no longer supplies security updates, a factory reset may remove current changes but cannot fix the underlying exposure.
If compromise is suspected, preserve logs and configuration before resetting the device, rotate management credentials from a known-clean system, and review other accounts that reused the same password. Rebooting alone is not a reliable cleanup method.
Does the seizure mean my router is clean?
No. It means the government disabled the identified QScan and QTRouter control platforms. There is no public, complete consumer device list that can prove a particular router was never involved. Owners should instead verify vendor support, firmware version, remote-management settings, administrator accounts, and unusual network behavior.

