The FBI and the Department of Justice announced Aug. 26 that they disrupted a global botnet operated by a China-linked hacking group known as QTFY, which had targeted hospitals and health systems along with other US critical infrastructure sectors.
What happened
The FBI and DOJ dismantled a botnet that the China-linked group QTFY, also known as QT and QTCYBER, used to attack US critical infrastructure. FBI San Diego and the FBI Cyber Division led the operation with DOJ partners, seizing multiple domains that the group's platforms relied on for functions such as communication and authentication. Investigators tied the group to Nanjing Xinjiuwei Network Technology, a company that sells stolen data and hacking services to Chinese military and intelligence agencies. QTFY had operated a scanning platform that searched the internet for vulnerable smart devices, including home routers and security cameras, infected thousands of them, and folded them into a botnet the group used to route and disguise malicious traffic through more than 130 countries.
The backstory
QTFY has operated since 2018 within a network of hackers-for-hire and government clients in the People's Republic of China, exploiting software vulnerabilities to attack US government agencies, power companies, telecommunications firms, and major hospital systems for nearly a decade. This operation follows other recent US actions against PRC state-sponsored hacking groups specifically, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the group Mustang Panda in 2025, disabled a Flax Typhoon botnet built from hundreds of thousands of infected devices in 2024, and disrupted a separate Volt Typhoon botnet in 2023.
The FBI has also taken action against financially motivated ransomware groups, separate from these nation-state campaigns. In July 2025, the Justice Department announced coordinated actions against the BlackSuit (Royal) ransomware group, seizing four servers, nine domains, and roughly $1 million in laundered proceeds. The takedown involved the FBI alongside the Department of Homeland Security's Homeland Security Investigations, the Secret Service, IRS Criminal Investigation, and international law enforcement partners in the United Kingdom, Germany, Ireland, France, Canada, Ukraine, and Lithuania.
Going deeper
QTFY built and maintained several branded tools that worked together. QScan, a vulnerability scanning and exploitation platform, identified weaknesses in victim networks and compromised internet-connected devices. QTRouter, an obfuscation network, then routed malicious traffic through those compromised devices and commercial proxy services to disguise the actors' true location. QTFY also ran botnet management platforms to control compromised devices, launch attacks, and add new nodes to the obfuscation network. The FBI and DOJ seized the domains these platforms depended on for communication and authentication.
What was said
AHA National Advisor for Cybersecurity and Risk John Riggi said "the need to identify and secure these ubiquitous devices is greater than ever."
In the know
A botnet is a network of internet-connected devices, such as home routers or security cameras, that a threat actor secretly infects and controls. Attackers use botnets to mask the true origin of their traffic, making malicious activity appear to come from everyday devices rather than the attacker's own infrastructure. This can make it harder for defenders to trace an intrusion back to its source, since traffic may appear to originate from a device near the victim's own network rather than overseas.
Why it matters
This disruption matters to hospitals and health systems specifically because QTFY has directly targeted healthcare before. According to a joint advisory, the group ran vulnerability scans against a US children's hospital in June 2021 and against a US hospital system in March 2026, though both attempts to gain network access were unsuccessful. The advisory also documents a case where the group succeeded against a healthcare target. In August 2020, QTFY actors used a Pulse Secure VPN exploit to attack a healthcare entity, prompting the victim to tell investigators that "attacking healthcare in a pandemic is just wrong." The operation also shows how blurred the line has become between criminal hacking groups and state intelligence services, QTFY operated as a hackers-for-hire network with direct ties to a company selling services to Chinese military and intelligence agencies. For healthcare organizations, the case is a reminder that ordinary internet-connected devices in their own facilities, such as routers and security cameras, can be turned into an adversary's infrastructure and used to mask attacks on their own networks or others.
The bottom line
The FBI and DOJ's seizure of QTFY's core domains rendered the group's scanning and obfuscation platforms unusable, but officials frame it as one part of an ongoing effort against PRC state-sponsored hacking rather than a final resolution. Healthcare organizations should review the joint cybersecurity advisory's indicators of compromise and mitigations, and take stock of internet-connected devices on their networks that could be exploited as part of similar botnet operations in the future.
FAQs
Why do hackers target ordinary devices like routers and cameras instead of computers directly?
These devices are often poorly secured and rarely monitored, making them easy to infect and useful for hiding an attacker's true location.
What counts as "critical infrastructure" in cybersecurity terms?
It refers to sectors essential to public safety and the economy, such as healthcare, energy, water, and telecommunications, whose disruption could cause widespread harm.
What does it mean when a hacking group is "state-sponsored" versus "hackers-for-hire"?
State-sponsored groups act on behalf of a government, while hackers-for-hire sell their services to any paying client.
What happens when the FBI "seizes domains" used by a hacking group?
Seizing domains cuts off the infrastructure a group relies on for communication and control, disabling their tools even if the individuals behind them remain at large.
