The Department of Justice and FBI announced on August 26 that they had seized three internet domains hard-coded into two Chinese state-sponsored hacking platforms, instantly disabling an eight-year espionage operation. The platforms QScan and QTRouter were employed by QTFY, a hackers-for-hire group working for Nanjing Xinjiuwei Network Technology Company and selling services to China’s Ministry of State Security and People’s Liberation Army. QScan scanned vulnerable IoT devices worldwide and fed compromised machines into QTRouter, which masked attack traffic through residential routers, commercial proxies and leased servers so intrusions appeared local rather than from China. Targets since 2018 included NASA, the Federal Reserve, the U.S. Senate, NIH, multiple cabinet departments and other critical infrastructure, with some intrusions successful in 2024 and broader campaigns reaching organizations in more than 130 countries. The hard-coded domains allowed the platforms to go dark simultaneously under court order. No specific data exfiltrated was disclosed, but a joint FBI-NSA advisory provides indicators of compromise for defenders. Attorney General Todd Blanche called the activity unacceptable ahead of a planned September summit with China; Beijing denied the allegations.