Chicago: 312-554-7550
St. Louis : 314-432-1661
Metro East IL : 618-346-8324
Central IL : 217-528-0500
This week, the Justice Department and FBI announced they’d seized the domains behind two hacking platforms, known as QScan and QTRouter, tied to a Chinese state-sponsored group. The headlines focused on the marquee victims: NASA, the Federal Reserve, the U.S. Senate, and the Department of Energy.
Those names make for a dramatic story. They also make it easy to miss the part that actually matters to most businesses.
QScan wasn’t only aimed at high-profile government networks. It also scanned the open internet and automatically infected vulnerable internet-connected devices. Those compromised devices could then become part of QTRouter, a network used to hide where later attacks were really coming from.
In other words, ordinary internet-connected devices and network equipment became part of the infrastructure behind a much larger hacking operation.
According to the Justice Department, a China-based group known as QTFY, operating through a company called Nanjing Xinjiuwei Network Technology, built and sold two connected hacking platforms.
QScan scanned internet-connected devices for known vulnerabilities and automatically infected vulnerable devices. QTRouter used compromised devices along with other infrastructure to relay malicious traffic and obscure the true origin of subsequent attacks.
The campaign reportedly ran from 2018 through 2026. Investigators say the platforms were sold as a paid service, with clients reportedly including China’s Ministry of State Security and People’s Liberation Army. The domain seizures made both platforms inoperable by cutting off infrastructure hardcoded into how they communicated.
It’s tempting to read a story like this and conclude it has nothing to do with a business that isn’t a federal agency or a power utility. That reading misses how campaigns like this actually work.
Botnets built on scanning tools like QScan don’t discriminate by company size. They discriminate by vulnerability.
A device is attractive to an operation like this not because of who owns it, but because it’s reachable from the internet and has a security weakness that can be exploited. An outdated device at a small manufacturer can be swept up just like vulnerable equipment anywhere else.
This pattern isn’t new, either. Federal agencies have disrupted other Chinese state-sponsored operations in recent years, including Volt Typhoon and Flax Typhoon, that similarly relied on compromised internet-connected devices to conceal or support malicious activity.
This is a recurring pattern in nation-state cyber operations, not an isolated incident.
You don’t need to be a defense contractor or hospital system to have equipment that fits the profile targeted by campaigns like this.
The relevant questions are much simpler than the headline suggests:
If the honest answer to any of these is “not sure,” that’s the actual takeaway from this story for your business.
Update router and network device firmware on a defined schedule. Network equipment can be easy to overlook because people don’t always think of a router or firewall as another computer running software that needs security updates.
Replace end-of-life network hardware. Equipment that no longer receives security updates from its manufacturer will never be patched again, no matter how many new vulnerabilities are discovered.
Reduce what’s directly exposed to the internet. Devices and services should be reachable only by the people and systems that actually need access, not open by default.
Check the federal advisory’s technical indicators if you manage your own network. The FBI and NSA published technical indicators of compromise tied to this campaign that IT teams can use when reviewing their own environments.
Ask your IT provider about your network equipment, not just your computers. Find out whether routers, firewalls, and other network devices are covered by ongoing monitoring, updates, and vulnerability management. These devices can easily be overlooked if nobody clearly owns that responsibility.
“This only matters to the government and big companies.” The infrastructure behind the campaign included compromised internet-connected devices that could be useful regardless of who owned them. Vulnerability, not company size alone, is what can make a device useful to an attacker.
“We’d know if one of our devices was compromised.” Devices repurposed this way may continue performing their normal functions while also being used to relay malicious traffic. A compromise doesn’t necessarily cause the kind of obvious outage that gets someone’s attention.
“Our antivirus covers this.” Antivirus and endpoint security primarily protect computers and servers. Routers, firewalls, and other connected devices need their own patching, configuration, and monitoring.
“Nation-state attacks are too sophisticated to defend against anyway.” The operation behind an attack may be sophisticated, but the opening doesn’t always have to be. An outdated device or known vulnerability can provide an opportunity for sophisticated attackers and ordinary cybercriminals alike.
An outdated device, an unnecessary internet connection, or a security gap nobody knows about can create an opening long before anyone realizes there’s a problem.
Our Free Cybersecurity & AI Risk Assessment reviews your current security environment to help identify vulnerabilities, unnecessary exposure, and other gaps that deserve attention. You’ll get a clearer picture of where your business stands and what should be addressed first.
Computerease can review your current defenses against the exact gaps this research identifies, MFA coverage, patch status, backup resilience, and vendor access, and show you where your real exposure is. Schedule a 15-minute discovery call to find out.
There’s no way to know based on the news alone. The FBI and NSA published technical indicators of compromise as part of their advisory that your IT or cybersecurity team can compare against your environment.
In many cases, the business itself may not be the ultimate target. A compromised internet-connected device can be valuable because attackers can use it to relay traffic and make malicious activity appear to originate somewhere other than its real source.
Yes. This operation supported state-sponsored cyber activity rather than functioning primarily as a direct extortion attempt against the businesses whose devices were compromised. However, many of the basic security practices that reduce this risk also help protect against ordinary cybercrime.
Confirm that all network equipment, not just computers, is being actively maintained. That means knowing what equipment you have, keeping supported devices updated, replacing end-of-life hardware, and identifying anything reachable directly from the internet that doesn’t need to be.
Not necessarily. In a campaign like this, the greater risk may be becoming an unwitting part of the infrastructure attackers use rather than being the ultimate target of the espionage itself.