Our takeDOJ seized domains behind QScan and QTRouter, two platforms China state-backed actors used against U.S. critical infrastructure. A seizure denies tooling; it doesn't evict footholds. If you run OT — and many OT operators are small shops — hunt for existing access now.Cyber Resilience desk
Sources (1)
- doj_press · doj_press
What this means for you — Security leader:The seized QScan and QTRouter platforms were used by China state-sponsored actors for targeting U.S. critical infrastructure. Review your internet-exposed assets, ensure OT and ICS systems are not reachable from the public internet, and confirm segmentation between IT and operational networks.
What this means for you — Lean IT orgs:China-linked hackers used these tools to attack critical infrastructure and other networks. Check that your remote-access systems, routers, and any industrial equipment are not exposed directly to the internet, and use strong unique passwords everywhere.
What this means for you — MSP:DOJ and FBI seized QScan and QTRouter, two platforms operated by China state-sponsored hackers targeting U.S. critical infrastructure. Audit client internet exposures, router configurations, and OT/ICS segmentation; prioritize any critical-infrastructure or regulated clients.
What this means for you — Researcher:DOJ/FBI seized QScan and QTRouter domains used by China state-sponsored actors against U.S. critical infrastructure. Monitor for any new indicators or successor infrastructure from the same groups.