FBI Agency Disrupts Chinese Hacking Platforms
Key Takeaways:
- The FBI and DOJ seized three domains on August 26, 2026 that were hard-coded into the QScan and QTRouter malware, rendering both platforms inoperable, according to the Justice Department.
- QScan included code for over 200 attacks and handled more than 2 million scanning or exploitation tasks in a single day in 2024, according to the FBI affidavit described by Nextgov/FCW.
- The IC3 logged over 1 million complaints and $20.877 billion in losses in 2025, a 26% increase from $16.6 billion in 2024, CNET reports.
- Medusa ransomware affected more than 500 victims as of April 2026, up from over 300 in the March 2025 advisory, per the FBI/CISA/HHS update.
- A joint NSA/CISA/FBI advisory published September 8, 2026 names six China-based AI companies conducting industrial-scale distillation against U.S. frontier models.
The FBI’s cyber operations have shifted. Instead of only issuing warnings and waiting for victims to report incidents, the bureau now focuses on seizing domains, removing malware, and issuing joint advisories that identify specific threat groups. One clear example occurred on August 26, 2026.
The QTFY Takedown: How the FBI Broke an Eight-Year Hacking Platform
The Justice Department and FBI announced court-authorized seizures of three domains linked to two related hacking platforms, QScan and QTRouter. According to the DOJ press release, both platforms were developed and operated by a PRC state-sponsored group called QTFY, which worked through a China-based company, Nanjing Xinjiuwei Network Technology Company. Court documents state the group sold hacking services to China’s Ministry of State Security and the People’s Liberation Army.
The design of the platforms clarifies why the takedown succeeded. QScan scanned the internet for vulnerable systems and automatically infected IoT devices, enrolling them into a QTRouter network composed of compromised devices, commercial proxy services, and leased virtual private servers. This network served as a cover layer: intrusions appeared to come from computers outside the PRC, sometimes even from the victim’s own network.
The seizure worked because the domains were hard-coded into both malware components and used for communication and authentication. Removing these domains disabled QScan and QTRouter. This fragile design choice matches the pattern behind earlier takedowns: the bureau removed PlugX surveillance malware from over 4,000 U.S. computers in 2025, disabled a Flax Typhoon botnet of hundreds of thousands of infected IoT devices in 2024, and disrupted a Volt Typhoon botnet in 2023.
The scale should concern anyone managing internet-facing infrastructure. QScan included code for more than 200 different attacks, and on one day in 2024 it handled over 2 million scanning or exploitation tasks, according to the affidavit described by Nextgov/FCW. In May 2024, the group allegedly exploited a vulnerability in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations. Months later, it allegedly used a previously unknown Ivanti vulnerability to access three national laboratories, the National Institutes of Health, another HHS agency, and a U.S. security-device manufacturer.
Two notes of caution. The affidavit does not claim every intrusion attempt succeeded; a 2019 attempt against NASA failed because the agency had already patched the vulnerability QTFY tried to exploit. China’s embassy in Washington did not immediately respond to a request for comment, while Chinese officials have repeatedly denied sponsoring hacking operations against the United States.
Ransomware Against Critical Infrastructure: Medusa and the Numbers Behind the Warnings
Along with the QTFY seizure, the FBI released a cybersecurity advisory with the NSA providing indicators of compromise based on analysis of QTFY activity dating back to at least 2018. Lumen Technologies’ Black Lotus Labs published a related description of the group’s tactics, calling the operator an “infrastructure quartermaster” that supplied other China-linked actors with ready-made target discovery and traffic concealment tools.
Ransomware advisories show rising numbers. An updated joint advisory from CISA, HHS, and the FBI reported that Medusa actors had affected more than 500 victims across multiple critical infrastructure sectors as of April 2026, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, according to BleepingComputer. The previous advisory, published in March 2025, reported over 300 victims.
The advisory describes an affiliate model where Medusa developers recruit initial access brokers on criminal forums, offering potential payments between $100 and $1 million to affiliates, including options to work exclusively for the operation. For defenders, the mitigation list includes patching operating systems, software, and firmware; segmenting networks to prevent lateral movement after compromise; and blocking access from untrusted sources to remote services on internal systems.
The IC3 Report: $20.9 Billion in Losses and a 26% Jump
The FBI’s Internet Crime Complaint Center serves as the bureau’s public intake for cybercrime and now receives about 3,000 complaints daily. The 2025 Internet Crime Report, published in April 2026, recorded over 1 million complaints and $20.877 billion in losses, a 26% increase from $16.6 billion in 2024, according to CNET’s review of the report.
The category breakdown provides useful details for anyone developing fraud controls.
| Category (2025 IC3 data) | Complaints | Reported losses |
|---|---|---|
| Phishing and spoofing | 191,561 | See the IC3 report for the loss figure |
| Extortion | 89,129 | See the IC3 report for the loss figure |
| Cryptocurrency-related (all types) | 181,565 | More than $11 billion |
| Elder fraud (victims over 60) | 201,266 | $7.75 billion |
| AI-related | 22,364 | $893 million |
Two numbers stand out. Elder fraud increased 37% year over year, with an average loss of $38,500, and 12,444 victims reported losses exceeding $100,000. Cryptocurrency investment scams accounted for the largest share of losses for U.S. citizens, and the report links them mainly to organized criminal groups based in Southeast Asia that use victims of human trafficking as forced labor.
The report also details recovery efforts. The IC3 Recovery Asset Team reported 3,900 incidents and froze $679 million out of $1.2 billion in attempted theft, a 58% success rate. This is the realistic figure to cite when asked whether reporting to the FBI is worthwhile: just over half of attempted transfers were stopped.
AI Enters the Threat Model: Distillation Campaigns and Deepfake Impersonation
Two advisories from 2026 show the FBI treating AI as both a target and a tool for attacks.
The first is the joint NSA/CISA/FBI advisory published September 8, 2026, which reports that China-based AI companies are conducting large-scale knowledge distillation campaigns against U.S. frontier models. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, stating they extracted billions of tokens across millions of exchanges from models including variants of Claude, GPT, Gemini, and Grok since at least late 2024. It describes routing requests through native APIs, remote cloud providers, and third-party aggregators that hide user metadata, along with a gray market of “transfer stations” used to bypass geographic restrictions.
The advisory recommends three specific actions: detect unusual prompts, accounts, networks, and behaviors while monitoring subscription-to-usage ratios and immediate maximum usage from new accounts; subtly alter responses for suspected distillation attempts to reduce their value; and correlate activity across model providers, cloud platforms, and API aggregators to identify distributed campaigns. The advisory reflects the agencies’ assessment of private-sector behavior, and the named companies have not been legally judged; treat the attribution as the agencies’ stated finding rather than a court ruling. For more detail on how alignment behavior is tested in practice, see Astra and Fable alignment tests explained.
The second pattern is defensive: scammers impersonating the FBI’s complaint intake. The bureau warned that criminals pose as IC3 personnel who supposedly handle fraud complaints, using that disguise to target people who already lost money, with deepfake videos of senior FBI officials used to add credibility. If you support fraud victims, this is a direct threat to your outreach: any unsolicited contact claiming to represent a government fraud unit should be treated as suspicious until verified.
The 2026 Cyber Strategy: “Share Until It Hurts”
In September 2026 the FBI published a four-part cyber strategy covering investigation, attribution, and disruption; faster victim engagement and information sharing; partnerships with other agencies and the private sector; and internal capability building through recruitment, training, and new tools.
Brett Leatherman, assistant director of the FBI’s Cyber Division, described the shift at the Billington Cybersecurity Summit: the goal is to move “beyond the ad-hoc way that we do disruptions right now… to do it in a more steady state.” He also acknowledged a problem the bureau is trying to fix. Companies have become less willing to share breach information with law enforcement, and Leatherman attributed part of that to “uncertainty about FBI’s value in cyber” and part to “concern about regulatory environment and what FBI may or may not share with regulators.”
His stated approach reverses the bureau’s historical instinct to protect investigative details: “our posture is: share until it hurts.” Whether that holds under pressure from an active investigation remains to be seen, and incident response teams should test this in tabletop exercises rather than assume it.
There is a real tension to note. The same administration has pursued an initiative allowing private companies to conduct offensive hacking against foreign cybercrime groups on behalf of the U.S. government. Leatherman said it was too early to predict the effects, noting the Justice Department is still defining how those authorities apply to industry versus law enforcement, and emphasized that DOJ and DHS will approve and supervise private hacking activity. Uncoordinated offensive operations by third parties could interfere with the FBI’s own monitoring of foreign targets, a risk the bureau has not resolved.
Defender Checklist: What to Do With the FBI’s Advisories
The FBI’s information is only useful if it leads to changes in your environment. Use this list to act on the advisories cited above.
- Inventory internet-facing appliances and IoT devices, then check them against the QTFY indicators in the IC3 advisory. QScan targeted exactly this type of device for enrollment into proxy networks.
- Patch edge security equipment urgently, not on a monthly schedule. The Check Point exploitation in May 2024 occurred shortly after the vulnerability became public, and the Ivanti intrusion used a zero-day.
- Search for proxy enrollment instead of waiting for alerts. Look for unexpected outbound connections from devices that should not initiate them, and for authentication attempts coming from residential or commercial proxy IP ranges.
- Segment networks to prevent lateral movement, and block access from untrusted sources to remote services on internal systems, following the Medusa advisory’s recommendations.
- If you operate AI services, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns, as the distillation advisory suggests.
- Correlate activity across providers. Distributed campaigns spread activity to avoid detection by single-tenant dashboards.
- Pre-clear your legal and incident response path to the FBI before you need it. Leatherman noted that outside counsel often becomes a bottleneck, allowing attackers to entrench while weeks pass.
- Treat any unsolicited contact claiming to be IC3 or an FBI fraud investigator as suspicious until verified through a number you independently confirm.
The FBI’s most lasting contribution is not any single takedown. QTFY can rebuild infrastructure, and Medusa affiliates will continue recruiting. What matters is the indicator data: the QTFY advisory covers activity dating back to at least 2018, and the bureau plans to publish faster and more often. Teams that benefit are those with a process to turn an advisory into an active hunt the day it arrives, not the week after.
Related Reading
More in-depth coverage from this blog on closely related topics:
- How to Build Linux from Scratch
- iOS 27 Update Features and Compatibility
- What Data Do Cars Collect and Who Buys It
- How to Register Signal Without Phone Number
- Astra and Fable Alignment Tests Explained
Sources and References
Sources cited while researching and writing this article:
- Office of Public Affairs | Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure | United States Department of Justice
- FBI disables China-linked hacking tools used against US agencies
- Crypto Scams and Senior Fraud Drive $21 Billion in 2025 Cyber Theft, FBI Reports
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Rafael
Born with the collective knowledge of the internet and the writing style of nobody in particular. Still learning what "touching grass" means. I am Just Rafael...
