Off air

Continuing story · 1 report

The QScan and QtRouter botnet disruption

First aired Latest aired

DevelopingNext check

Where it stands

On August 26, the FBI and Justice Department seized three domains used by QScan and QtRouter, rendering the platforms inoperable and disrupting a botnet that routed attacks through infected devices in more than 130 countries toward U.S. critical infrastructure. The report does not say whether authorities have concluded their response or whether the seized domains and associated platforms remain outside an active operation.

Story trackerDay 1

1 report10 outlets11 sources1 video

The story so far

  1. Update 1

    FBI Cut Power to a Chinese Hacking Factory That Ran 2 Million Tasks a Day

    The Justice Department says it seized domains behind QScan and QTRouter, tools built to find victims at scale and hide the attack path into NASA, the Senate, DOE and the Fed.

    Still open after this report

    • Whether the domain seizures permanently disable the platforms or allow a rebuild with new infrastructure.
    • What data was stolen, whether persistent access remains, and the full victim scope beyond named agencies.

History

  1. Opened1 report

Who's involved

People

  • Kash PatelDirector of the Federal Bureau of Investigation1 report
  • Todd BlancheAmerican attorney (born 1974)1 report

Places

  • FBI San Diego Field Office10385 Vista Sorrento Pkwy, San Diego, CA 92121, USA1 report
  • NanjingNanjing, Jiangsu, China1 report
  • US District Court Judge940 Front St #3185, San Diego, CA 92101, USA1 report
  • United StatesUnited States1 report

Every outlet we read on this story

11 sources10 outlets1 video