Back to news
Cybersecurity Alert
August 26, 2026 by EmailMeNow IT Consulting

DOJ and FBI Seize QTFY Platforms Used Against NASA, the Fed, and the Senate

DOJ and FBI seized domains hard-coded into China-nexus QScan and QTRouter platforms used against NASA, the Federal Reserve, DOJ, and the U.S. Senate. Audits (ideal 100%): nih.gov 78%, energy.gov 73%, nsa.gov 55% — 0/11 at 100%. Login.gov documents YubiKey and authenticator apps.

Source: U.S. Department of Justice · FBI

NewsFBIDOJNASAMFAYubiKeyAuthenticator AppsCybersecurity
Operations-room laptops showing a generic domain marked taken down, with a muted U.S. flag in the background

The Justice Department and FBI announced court-authorized domain seizures on August 26, 2026 that they say made two complementary China-nexus hacking platforms — QScan and QTRouterinoperable. DOJ press release 26-972 names a PRC state-sponsored group QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company, as the operator. Paying customers, DOJ says, include the PRC Ministry of State Security and the People’s Liberation Army.

Among the victims of QTFY computer intrusion activity, DOJ lists NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate. Reuters (via HuffPost) and UPI repeated the same disruption. The Justice Department posted the announcement the same day. Anadolu Agency reports three seized domains; this post does not republish alleged malware hostnames.

This is a platform disruption, not a how-to and not a named-org “data dump.” DOJ has not published a stolen-record count. It is not a duplicate of the federal agencies email-security listicle (score snapshot) or the FBI NCII PSA (social-account phishing).

Operations-room laptops showing a generic domain marked taken down, with a muted U.S. flag in the background

Snapshot

FieldDetail
LeadDOJ OPA 26-972 (Aug 26, 2026)
CourtAffidavit unsealed, Southern District of California
GroupQTFY via Nanjing Xinjiuwei; customers include MSS and PLA
Platforms seizedQScan + QTRouter (hard-coded domains used for C2/auth)
Named victimsNASA, Federal Reserve, Energy, DOJ, HHS, NIH, U.S. Senate
CourtListenerRECAP not yet indexing "QScan" AND "QTRouter"; Texas federal 0 for "QTFY" (Aug 26)

What DOJ says the platforms did

DOJ describes a two-part service, not a single emailed lure:

PieceRole (DOJ wording)
QScanScans and automatically infects thousands of IoT devices worldwide
QTRouterObfuscation network: compromised IoT, commercial proxies, leased VPS
EffectIntrusion traffic can look local to the target, not PRC-origin
SeizureHard-coded domains were used for communication and authentication

The Record adds FBI Assistant Director Brett Leatherman: devices in more than 130 countries; routers and cameras among the IoT classes; the firm also sells stolen data and hacking services. The Record says investigators followed the infrastructure from 2018 through a U.S. Senate attack this year — the affidavit, it reports, does not name senators or committees.

Lumen Black Lotus Labs published a matching “quartermaster” write-up the same day: The infrastructure quartermaster. DOJ says FBI and NSA also released a QTFY indicators advisory covering activity back to at least 2018. This post does not copy IoCs.

Home routers and a camera on a shelf with cables running toward a dark network closet

What is confirmed — and what is not

DOJ’s victim list is computer intrusion activity. It is not a public inventory of exfiltrated files.

ClaimStatus
Named U.S. agencies were QTFY intrusion victimsDOJ (Aug 26)
Hospitals, telecom, power, finance, defense contractorsThe Record citing the affidavit (unnamed orgs)
Four unnamed companies in the U.S. and South KoreaReuters via HuffPost
2019 NASA Pulse Secure VPN attemptThe Record; Anadolu says it failed because NASA had already patched
Prior PRC disruptions (Mustang Panda PlugX, Flax Typhoon, Volt Typhoon)DOJ (separate operations)

Do not treat a patched 2019 NASA attempt as the whole NASA story — DOJ still lists NASA among intrusion victims. Do not invent a nationwide victim count.

MFA: YubiKey, Google Authenticator, PIV

QTFY hid behind other people’s devices. Phishing-resistant MFA on Login.gov and agency PIV still matters for the accounts those agencies expose to the public and to staff. Rechecked August 26, 2026.

PortalYubiKey / FIDOOpen TOTPGrade
Login.govYes (security key)Yes (auth app)Strong
NASA Guestvia Login.gov (guest help)via Login.govStrong
NASA workforcePIV (NPR 2810.1F)Not documentedStrong
NASA NAS (HECC)RSA SecurID (policy)NoPartial

YubiKey / Google Authenticator: Login.gov documents FIDO security keys and an authentication-app (open TOTP) path — Google Authenticator-class apps are the documented consumer option, plus PIV/CAC for eligible government emails. NASA Guest federates to Login.gov. Agency staff PIV/CAC is Strong hardware, not open TOTP. The NAS supercomputing facility still documents RSA SecurID for remote access — Partial, not YubiKey.

SMS/voice remains a weaker Login.gov option. Enroll a security key. Same rule as the MFA directory.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and smart ID card beside a generic authenticator code screen

Independent cybersecurity audits

EmailMeNow domain audits on August 26, 2026. 100% is the ideal. 0 of 11 reach it. These scores are public identity / transport / website posture on the real agency hosts. They do not measure whether QTFY still has access anywhere, and they do not validate a lookalike URL.

OrganizationDomainOverallvs 100%
NIHnih.gov78%−22
Energy Departmentenergy.gov73%−27
HHShhs.gov71%−29
U.S. Senatesenate.gov68%−32
Justice Departmentjustice.gov66%−34
NASAnasa.gov65%−35
FBIfbi.gov64%−36
Federal Reservefederalreserve.gov63%−37
Login.govlogin.gov63%−37
Lumenlumen.com58%−42
NSAnsa.gov55%−45
DomainIdentityTransportWebsite
nih.gov65%45%98%
energy.gov95%45%43%
hhs.gov90%70%37%
senate.gov95%45%37%
justice.gov80%45%40%
nasa.gov80%45%37%
fbi.gov75%45%40%
federalreserve.gov75%45%37%
login.gov65%100%40%
lumen.com65%15%37%
nsa.gov55%45%37%

How to read this: NIH leads at 78% on a strong website score; Energy leads identity at 95% and still misses 100%. Login.gov is the only host here with 100% transport — and still 63% overall. NSA trails at 55%. The June federal agencies listicle used a different agency set and older scores (FBI 65% then vs 64% on this pass).

Audit links: nih.gov · energy.gov · hhs.gov · senate.gov · justice.gov · nasa.gov · fbi.gov · federalreserve.gov · login.gov · lumen.com · nsa.gov

Padlocks stop short of a TARGET finish line, illustrating domain audits that miss the 100 percent ideal

Illustration only — scores are in the tables above, not in the artwork.

Website stack note

Passive website-tech probes on August 26, 2026:

DomainStack signal
energy.govDrupal 8 (latest 11.4.5)
nih.govDrupal 10 (latest 11.4.5)
justice.govDrupal 11 behind 11.4.5
nasa.govWordPress, version hidden; Sectigo TLS into Dec 11, 2026
senate.govStack undetected; jQuery 1.11.3 (pre-3.5 XSS-class fixes)
login.govStack undetected; Let’s Encrypt TLS into Oct 4, 2026 (38d)
nsa.gov / hhs.govHTTP→HTTPS redirect not confirmed on probed hosts
federalreserve.gov, fbi.gov, lumen.comNo notable CMS aging flags in this pass

Stack hygiene on a .gov homepage does not prove an IoT botnet is gone.

Blacklist and lookalike domains

Email blacklist checks (public DoH, August 26, 2026): nasa.gov, federalreserve.gov, energy.gov, justice.gov, hhs.gov, nih.gov, senate.gov, fbi.gov, nsa.gov, lumen.com, and login.gov were clear on mail/domain lists we can query. Federal Reserve, NIH, and FBI showed SPFBL notes on CDN/web IPs only — not counted as mail reputation hits. senate.gov had no MX in this pass.

DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only):

Brand scannedCheckedTo reviewBEC staging
nasa.gov80120
fbi.gov69110
justice.gov116110
senate.gov106111
federalreserve.gov201102

High-interest registered names (investigate; not QTFY infrastructure):

LookalikeTechniqueNote
senate.devtld-swapBEC staging (NS, MX)
federalreserve.iotld-swapBEC staging (NS, MX)
federalreserve.orgtld-swapBEC staging (NS, MX)
federalreserve.comtld-swapMX points at the real Fed mail host

The scanner also flagged nsa.gov as an “omission” of nasa.gov — that is NSA, a different agency, not a NASA clone. Pair monitoring with Cybersquat Domain Monitoring.

CourtListener and weekly scan sources

CourtListener RECAP on August 26, 2026: 0 hits for "QScan" AND "QTRouter". Quoted "QTFY" is too noisy as a ticker-style string and returned 0 in Texas federal courts (txsd / txed / txnd / txwd). SDCA dockets filed in early August 2026 that matched a generic “seizure” query were unrelated account warrants — the QTFY affidavit is unsealed per DOJ but not yet in the RECAP index we queried.

SourceFinding
DOJ / FBIPrimary — PR 26-972 + SDCA affidavit
Lumen Black Lotus LabsSame-day quartermaster TTP write-up
Reuters / UPI / The RecordCorroboration; no stolen-record count
MERENA / DeXpose / GalaxyWardenNot a leak-site listing
SEC Item 1.05Not applicable (federal agencies, not issuers)

Sources: DOJ OPA 26-972 (Aug 26, 2026); The Record; Reuters via HuffPost; UPI; Anadolu Agency; Lumen Black Lotus Labs; DOJ on X. Independent EmailMeNow domain audits, website-tech probes, blacklist checks, cybersquat scans, and CourtListener RECAP August 26, 2026. MFA grades reflect public documentation, not a private account enumeration.

Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.