Skip to main content

Computerease

The Chinese State-Sponsored Botnet the FBI Just Took Down Was Built on Devices You Regularly Use

Chinese State-Sponsored Botnet Takedown: What It Means for Your Business

This week, the Justice Department and FBI announced they’d seized the domains behind two hacking platforms, known as QScan and QTRouter, tied to a Chinese state-sponsored group. The headlines focused on the marquee victims: NASA, the Federal Reserve, the U.S. Senate, and the Department of Energy.

Those names make for a dramatic story. They also make it easy to miss the part that actually matters to most businesses.

QScan wasn’t only aimed at high-profile government networks. It also scanned the open internet and automatically infected vulnerable internet-connected devices. Those compromised devices could then become part of QTRouter, a network used to hide where later attacks were really coming from.

In other words, ordinary internet-connected devices and network equipment became part of the infrastructure behind a much larger hacking operation.

What Actually Happened

According to the Justice Department, a China-based group known as QTFY, operating through a company called Nanjing Xinjiuwei Network Technology, built and sold two connected hacking platforms.

QScan scanned internet-connected devices for known vulnerabilities and automatically infected vulnerable devices. QTRouter used compromised devices along with other infrastructure to relay malicious traffic and obscure the true origin of subsequent attacks.

The campaign reportedly ran from 2018 through 2026. Investigators say the platforms were sold as a paid service, with clients reportedly including China’s Ministry of State Security and People’s Liberation Army. The domain seizures made both platforms inoperable by cutting off infrastructure hardcoded into how they communicated.

Why This Isn’t Just a Government Problem

It’s tempting to read a story like this and conclude it has nothing to do with a business that isn’t a federal agency or a power utility. That reading misses how campaigns like this actually work.

Botnets built on scanning tools like QScan don’t discriminate by company size. They discriminate by vulnerability.

A device is attractive to an operation like this not because of who owns it, but because it’s reachable from the internet and has a security weakness that can be exploited. An outdated device at a small manufacturer can be swept up just like vulnerable equipment anywhere else.

This pattern isn’t new, either. Federal agencies have disrupted other Chinese state-sponsored operations in recent years, including Volt Typhoon and Flax Typhoon, that similarly relied on compromised internet-connected devices to conceal or support malicious activity.

This is a recurring pattern in nation-state cyber operations, not an isolated incident.

What Your Business Could Have in Common With This Story

You don’t need to be a defense contractor or hospital system to have equipment that fits the profile targeted by campaigns like this.

The relevant questions are much simpler than the headline suggests:

  • Do you have routers, firewalls, or other network equipment running firmware that hasn’t been updated in months or years?
  • Are any devices or services reachable directly from the internet that don’t actually need to be?
  • Do you know, with confidence, what’s connected to your network right now, including older equipment nobody thinks about?
  • Has anyone reviewed your network equipment specifically, separate from your computers and servers, for known vulnerabilities?

If the honest answer to any of these is “not sure,” that’s the actual takeaway from this story for your business.

What to Actually Do About It

Update router and network device firmware on a defined schedule. Network equipment can be easy to overlook because people don’t always think of a router or firewall as another computer running software that needs security updates.

Replace end-of-life network hardware. Equipment that no longer receives security updates from its manufacturer will never be patched again, no matter how many new vulnerabilities are discovered.

Reduce what’s directly exposed to the internet. Devices and services should be reachable only by the people and systems that actually need access, not open by default.

Check the federal advisory’s technical indicators if you manage your own network. The FBI and NSA published technical indicators of compromise tied to this campaign that IT teams can use when reviewing their own environments.

Ask your IT provider about your network equipment, not just your computers. Find out whether routers, firewalls, and other network devices are covered by ongoing monitoring, updates, and vulnerability management. These devices can easily be overlooked if nobody clearly owns that responsibility.

Common Misunderstandings About This Story

“This only matters to the government and big companies.” The infrastructure behind the campaign included compromised internet-connected devices that could be useful regardless of who owned them. Vulnerability, not company size alone, is what can make a device useful to an attacker.

“We’d know if one of our devices was compromised.” Devices repurposed this way may continue performing their normal functions while also being used to relay malicious traffic. A compromise doesn’t necessarily cause the kind of obvious outage that gets someone’s attention.

“Our antivirus covers this.” Antivirus and endpoint security primarily protect computers and servers. Routers, firewalls, and other connected devices need their own patching, configuration, and monitoring.

“Nation-state attacks are too sophisticated to defend against anyway.” The operation behind an attack may be sophisticated, but the opening doesn’t always have to be. An outdated device or known vulnerability can provide an opportunity for sophisticated attackers and ordinary cybercriminals alike.

Not Sure Where Your Network Is Exposed?

An outdated device, an unnecessary internet connection, or a security gap nobody knows about can create an opening long before anyone realizes there’s a problem.

Our Free Cybersecurity & AI Risk Assessment reviews your current security environment to help identify vulnerabilities, unnecessary exposure, and other gaps that deserve attention. You’ll get a clearer picture of where your business stands and what should be addressed first.

Not Sure Where Your Business Actually Stands?

Computerease can review your current defenses against the exact gaps this research identifies, MFA coverage, patch status, backup resilience, and vendor access, and show you where your real exposure is. Schedule a 15-minute discovery call to find out.

Download Your Free AI Policy Template

Frequently Asked Questions

There’s no way to know based on the news alone. The FBI and NSA published technical indicators of compromise as part of their advisory that your IT or cybersecurity team can compare against your environment.

In many cases, the business itself may not be the ultimate target. A compromised internet-connected device can be valuable because attackers can use it to relay traffic and make malicious activity appear to originate somewhere other than its real source.

Yes. This operation supported state-sponsored cyber activity rather than functioning primarily as a direct extortion attempt against the businesses whose devices were compromised. However, many of the basic security practices that reduce this risk also help protect against ordinary cybercrime.

Confirm that all network equipment, not just computers, is being actively maintained. That means knowing what equipment you have, keeping supported devices updated, replacing end-of-life hardware, and identifying anything reachable directly from the internet that doesn’t need to be.

Not necessarily. In a campaign like this, the greater risk may be becoming an unwitting part of the infrastructure attackers use rather than being the ultimate target of the espionage itself.

Key Takeaways

  • QScan scanned for and infected vulnerable internet-connected devices, while QTRouter used compromised devices and other infrastructure to help conceal the source of malicious activity.
  • Chinese state-sponsored actors have repeatedly used compromised internet-connected equipment as part of larger cyber operations.
  • Businesses of any size can have vulnerable equipment if network devices run outdated firmware, are no longer supported, or are unnecessarily exposed to the internet.
  • Endpoint security on computers doesn’t replace proper patching, configuration, and monitoring of routers, firewalls, and other network equipment.
  • The FBI and NSA have published technical information that IT and cybersecurity teams can use when evaluating potential exposure.