US Seizure Cuts Off QTFY’s Hidden Traffic Layer

DOJ and FBI seized domains tied to QScan and QTRouter, the China-linked platforms QTFY used to scan, infect, and route attacks against U.S. federal agencies and critical infrastructure. The disruption also hit the layer that made those operations look like they came from ordinary IoT devices, leased proxies, or even local networks. QScan hunted for vulnerable internet-connected devices and pulled them into a botnet; QTRouter then used that mix of infected routers, cameras, and proxy infrastructure to hide where the traffic really came from. In practice, that means a victim could misread a foreign intrusion as domestic, or mistake a remote operator for something inside its own network. For defenders that lean on source IP or geolocation to sort internal from external activity, the lesson is that those signals can be staged. The takedown removes one masking service, but it does not change the fact that compromised devices and proxy chains can still distort attribution and forensic timelines elsewhere.

Part of the PlainSec briefing for 2026-08-26

Editions

Sources