The Quiet Relay: How China-Linked Hackers Turned IoT Devices Into Espionage Highways
A home router usually fails quietly. It slows down, drops a connection, or becomes too old for its manufacturer to support. But the same device can also become something more useful to an intelligence service: a relay point that makes an attack appear to come from inside the country it is targeting.
That is the significance of the U.S. government’s August 26, 2026 disruption of QScan and QTRouter, platforms that prosecutors allege were operated by a China-based company for Chinese government and military customers. The case describes an industrialized service for finding vulnerable internet-connected devices, infecting them, and routing hostile traffic through them. The result was a hidden network of ordinary machines that could help attackers scan targets, deliver malware, and conceal where an operation began. The Record, Nextgov
The public record does not establish that a particular American office printer or suburban Linksys router served as a node in this operation. That image is plausible, but it would be an invention to present it as a documented fact. The evidence does establish something more consequential: routers, cameras, firewalls, network-attached storage devices, and other embedded systems have become usable infrastructure in foreign cyber operations. They are no longer merely targets or victims. Some can function as the cover, staging ground, and traffic relay for attacks against government agencies and critical services.
The central question is therefore not whether China has “converted the Internet of Things” into one unified intelligence network. Public evidence does not support that sweeping claim. It supports a narrower and still serious conclusion: China-linked actors have used large, changing networks of compromised devices as operational infrastructure, and the model reduces the value of traditional assumptions about where an attack originates.
QScan searched. QTRouter hid the traffic.
According to court records described in reporting by cybersecurity journalists, QScan and QTRouter performed different jobs.
QScan was allegedly a scanning and exploitation platform. It searched the internet for vulnerable routers, cameras, and other connected equipment, then automated attempts to compromise them. The affidavit reportedly attributed more than 200 attack methods to the platform. On one day in 2024, QScan processed more than two million scanning or exploitation tasks, according to the FBI affidavit as described by Nextgov. That number measures tasks processed by the system, not successful compromises or unique victims. Nextgov
QTRouter allegedly handled the next problem: concealment. It routed traffic through compromised devices, commercial proxy services, and rented servers. An operator using the system could make traffic appear to come from an infected router in the United States, a commercial proxy in another country, or a rented server that had no obvious connection to China.
The FBI and Justice Department seized three internet domains associated with the platforms. The domains were reportedly hard-coded into the tools and required for functions such as communication and authentication. Seizing them therefore disrupted the platforms themselves rather than merely blocking a few command-and-control addresses. The operation was court-authorized, but the allegations remain allegations. A seizure is not a criminal conviction, and the public reporting does not establish that every attempted intrusion succeeded. The Record, Nextgov
Investigators attributed QTFY, the group associated with the platforms, to Nanjing Xinjiuwei Network Technology Company, a private Chinese firm. Court records reportedly said the company sold hacking services to customers including China’s Ministry of State Security and the People’s Liberation Army. The FBI also described the operator as part of a larger network of hackers-for-hire and government clients in China. Those claims come from U.S. government filings and statements. Chinese officials have repeatedly denied that Beijing sponsors hacking operations against the United States, and the Chinese embassy in Washington had not immediately responded to requests for comment in the reporting available on August 26. The Record, Nextgov
The important development is not simply that two tools were taken offline. It is the apparent division of labor. One platform found and recruited machines. The other turned those machines into a distributed cover network. That arrangement resembles an infrastructure service more than a single intrusion.
The reported targets stretched across the U.S. government and private infrastructure
The government’s allegations place QTFY activity across a wide range of American institutions.
Reported targets included:
- NASA
- the Federal Reserve
- the U.S. Senate
- the Departments of Energy, Justice, and Health and Human Services
- the National Institutes of Health
- national laboratories
- hospitals and medical centers
- telecommunications providers
- power companies
- banks and other financial institutions
- insurance organizations
- defense contractors
- security-device manufacturers
The list combines attempted intrusions, scanning, exploitation activity, and other forms of targeting. It should not be read to mean that every organization suffered a successful breach.
One example illustrates the distinction. Investigators reportedly traced a 2019 attempt against NASA to infrastructure and email addresses in China, but the attempt failed because NASA had already patched the vulnerability in the Pulse Secure VPN product that the attackers tried to exploit. Another allegation concerns a 2024 campaign against Check Point security equipment. Court records reportedly said QTFY exploited the flaw soon after it became public and obtained server settings and user-account information from more than 300 U.S. organizations. The public account does not establish that all of those organizations experienced the same level of compromise. Nextgov
The alleged targets matter because they show how a relay network can support different missions. A foreign intelligence service might use one compromised device to scan for exposed systems, another to access a victim, and a third to move stolen data. The devices do not need to belong to the ultimate target. They only need to sit in a useful location, accept the attacker’s traffic, and remain unnoticed long enough to serve the operation.
How an ordinary device becomes a foreign relay
A botnet is a network of devices controlled without their owners’ permission. The device may be a router, camera, digital video recorder, firewall, network-attached storage system, or another computer with an internet connection.
The conversion usually follows a basic sequence:
- An automated scanner identifies an exposed device.
- The operator tests known vulnerabilities, weak credentials, or exposed management services.
- A payload establishes remote access.
- The device reports basic information about itself and its connection.
- The operator adds it to a command-and-control network.
- Traffic is routed through the device or the device is used to launch further activity.
- The operator replaces, abandons, or refreshes the node when it becomes unsafe.
The FBI, National Security Agency, and Cyber National Mission Force described this model in a September 2024 advisory about a botnet controlled by Integrity Technology Group, another China-based company. The advisory said the botnet had maintained tens to hundreds of thousands of compromised devices and contained more than 260,000 devices as of June 2024. The devices were observed across North America, South America, Europe, Africa, Southeast Asia, and Australia. FBI, NSA, and CNMF
That advisory described a Mirai-based system designed to compromise Linux-based routers and IoT equipment. After compromise, a device could download a payload, connect to a command-and-control server over TLS on port 443, report system and network information, and in some instances delete the payload to make detection harder. The same document linked the infrastructure to activity publicly associated with Flax Typhoon, RedJuliett, and Ethereal Panda, while warning that private-sector and government tracking labels do not always correspond exactly. FBI, NSA, and CNMF

This is not a special property of Chinese operations. The Mirai source code became public in 2016 and has since been adapted into many botnets. What the U.S. government says has changed in China-linked activity is the scale and strategic use of these networks. A joint advisory released in April 2026 by CISA, the FBI, NSA, and allied agencies described a shift away from individually rented infrastructure toward large networks of compromised devices. It called these networks “covert networks” and said they could be used during reconnaissance, malware delivery, command-and-control communication, data theft, and ordinary internet browsing by attackers seeking to avoid attribution. CISA and international partners
Why domestic-looking traffic matters
Internet traffic carries technical clues about where it came from, but those clues describe the immediate connection rather than necessarily identifying the person or organization controlling it.
If an attacker in China connects directly to an American target, the target may see an IP address associated with a Chinese network, a hosting provider, or a known intelligence-related infrastructure cluster. That does not prove who operated the connection, but it provides investigators with a starting point.
A compromised American router changes the first impression. The target may see a residential or small-business internet service provider. The traffic appears to have entered from a domestic customer, perhaps in the same region as the victim. A compromised camera or router inside a business may make the traffic appear to come from a normal American organization rather than from a foreign operator.
The mechanism is not geographic “spoofing” in the narrow sense of changing a physical location. The relay is real. The traffic genuinely passes through the domestic device. What changes is the relationship between the observed source and the actual operator.
That distinction creates several problems for defenders.
Attribution becomes a chain, not an address
Investigators must determine whether the apparent source is the attacker, an innocent victim, a rented proxy, or a compromised intermediary. The task requires tracing commands, timing, malware, authentication behavior, infrastructure registrations, payment records, and links among multiple servers and devices.
A single attack may involve several hops. Each hop can obscure the previous one, and an operator can replace one node without rebuilding the whole network.
Blocking becomes riskier
Blocking an IP address associated with a residential provider may cut off a legitimate customer, a hospital, a small business, or an entire class of users. Blocking a cloud provider can affect unrelated tenants. A domain associated with a compromised device may have no obvious malicious reputation.
CISA’s 2026 advisory warned that some covert networks also serve legitimate customers. That mixture makes simple reputation-based blocking less reliable. CISA and international partners
Threat intelligence can decay quickly
Traditional indicators of compromise often include IP addresses, domains, and hashes. Those indicators remain useful, but a large proxy network weakens their shelf life. The same operator can move through thousands of devices, and multiple threat actors may use the same network.
The April 2026 advisory said a single covert network could be used by multiple China-nexus actors. That possibility complicates efforts to map infrastructure to a single group or mission. CISA and international partners
The hardware problem is ordinary and persistent
The QScan allegations focus attention on a weakness that has existed for years: internet-connected equipment often outlives its security support.
The Justice Department’s January 2024 account of the Volt Typhoon-linked KV Botnet said most of the routers in that network were Cisco and Netgear models that had reached end-of-life status. Their manufacturers no longer supplied security patches or software updates. The FBI-led operation obtained court authorization to remove malware from hundreds of U.S.-based small-office and home-office routers and to block their communications with botnet infrastructure. U.S. Department of Justice
End-of-life equipment is only part of the problem. The 2024 FBI and NSA advisory noted that many devices in the Integrity Technology-controlled botnet were likely still supported by their vendors. A device can therefore be vulnerable even when its product line has not been abandoned. FBI, NSA, and CNMF
Common entry points include:
- publicly known software vulnerabilities;
- default or weak administrative passwords;
- management interfaces exposed to the internet;
- remote administration enabled unnecessarily;
- firmware that is difficult to update;
- vendors that stop issuing patches;
- insecure supply chains or undocumented components;
- devices deployed without centralized inventory;
- equipment that owners do not realize is internet-accessible.
The weakness is partly technical and partly economic. A consumer router may cost less than a day of professional security work. A small organization may have no accurate inventory of its cameras, firewalls, printers, storage appliances, and remote-access gateways. An internet service provider may know that a device is producing unusual traffic without being able to repair it remotely or identify the person responsible for its configuration.
The result is a large population of equipment that is connected, useful, and poorly supervised.
Volt Typhoon, Flax Typhoon, and the limits of group labels
The QScan and QTRouter case overlaps with earlier China-linked operations in its use of compromised infrastructure, but the public evidence does not show that all of these campaigns were one operation.
The Justice Department and the FBI previously linked the KV Botnet to Volt Typhoon, a China-sponsored group accused of gaining access to U.S. critical infrastructure and positioning itself for possible use during a future crisis. The January 2024 DOJ announcement said the botnet helped conceal activity directed at communications, energy, transportation, and water organizations. U.S. Department of Justice
The 2026 CISA advisory described a separate network called Raptor Train, which it said infected more than 200,000 devices worldwide in 2024 and was controlled by Integrity Technology Group. The advisory connected that company to activity attributed by the FBI to Flax Typhoon. It also said the KV Botnet was mainly composed of vulnerable Cisco and Netgear routers, while Raptor Train included routers, cameras, video recorders, firewalls, and network-attached storage devices. CISA and international partners
These cases suggest a shared operational pattern:
- compromise large numbers of edge devices;
- use them to hide or route traffic;
- separate the infrastructure layer from the intrusion team;
- refresh the network as devices are cleaned or blocked;
- make attribution depend on behavior and infrastructure links rather than source addresses alone.
They do not prove that Volt Typhoon, Flax Typhoon, and QTFY share one command structure. The FBI itself cautioned that public and government naming systems may not map to one another on a one-to-one basis. FBI, NSA, and CNMF
The evidence cited here does not establish a relationship between QScan or QTRouter and Salt Typhoon. A responsible account should therefore describe a broader Chinese use of compromised infrastructure without collapsing distinct operations into one group.
What the takedown did, and what it did not do

The QScan and QTRouter seizure reportedly made both platforms inoperable by taking control of domains embedded in their software. That is a meaningful disruption because it attacked the management layer used to authenticate and coordinate the tools.
It did not automatically clean every infected device.
That distinction appeared in earlier operations. The DOJ’s 2024 KV Botnet action included removing malware from victim routers and blocking communications with botnet infrastructure. The 2026 QScan reporting, by contrast, describes a domain seizure that disabled the platforms. The public material supplied for this article does not establish how many devices were infected by QTFY, how many were remediated, or how many may remain vulnerable to reinfection. U.S. Department of Justice, The Record
A takedown can also produce a temporary effect. Operators may register replacement domains, alter hard-coded infrastructure, exploit new vulnerabilities, or move to another covert network. The long-term value of the operation depends on whether defenders patch or replace exposed equipment and whether investigators can use the seized infrastructure to identify victims.
That is why public takedowns should not be mistaken for a final accounting of the threat.
The United States does not have a complete census of vulnerable IoT devices
No single figure in the public evidence provides an accurate count of all vulnerable internet-connected devices deployed in the United States.
Government and private-sector researchers can observe portions of the internet through scanning, telemetry, sinkholes, customer data, incident reports, and voluntary disclosures. Those methods can estimate exposed services and identify known botnets. They cannot reliably count every device, determine whether every visible device is vulnerable, or establish whether a device is actively compromised.
Several factors make the problem resistant to precise measurement:
- devices may be hidden behind network address translation;
- owners may not know the model or firmware version;
- vulnerable devices may be offline when measured;
- some equipment is reachable only from internal networks;
- scanning data can overcount services or miss intermittent systems;
- vulnerability status depends on configuration, not only model;
- vendors may use different support and patching practices;
- compromised devices can change behavior to avoid detection.
The numbers in public advisories therefore describe identified networks, not the total exposure. The 260,000-device figure for the Integrity Technology botnet is a count associated with that botnet at a particular time. The more than 200,000 devices associated with Raptor Train is likewise a measurement of a particular network and period. Neither number is a national inventory of vulnerable devices. FBI, NSA, and CNMF, CISA and international partners
This uncertainty has operational consequences. An organization cannot defend equipment it does not know it owns, and a government cannot easily estimate how much domestic connectivity might be available to an adversary during a crisis.
Homes, businesses, ISPs, and cloud providers carry different risks
A compromised residential router can expose the owner’s traffic and provide a domestic exit point. A compromised business device can give an attacker a more credible location, better bandwidth, and access to other internal systems. A compromised device inside a government facility or telecommunications network can provide both concealment and a foothold.
Internet service providers face a difficult balance. They can detect scanning, unusual outbound traffic, command-and-control connections, or sudden changes in device behavior. But notification may be difficult when customers use unsupported equipment, when the provider cannot see the internal network, or when remediation requires replacing hardware.
Enterprises face a different problem. Security teams often monitor servers and endpoints while overlooking appliances that run specialized firmware. A camera system, firewall, storage device, or printer may have administrative access, process sensitive data, or sit on a network segment that defenders rarely inspect. An appliance that cannot run a conventional endpoint agent can remain invisible until it generates a recognizable indicator.
Cloud and proxy providers also become part of the chain. QTRouter reportedly combined compromised devices with commercial proxies and leased servers. That mixture allows malicious traffic to blend with legitimate customer activity and forces providers to distinguish abuse from ordinary use. The Record, CISA and international partners
The foreign comparison is real, but the evidence is uneven
Botnets and proxy networks are not uniquely Chinese. Mirai-derived malware has been reused by criminal groups and state-linked actors, and Russia, Iran, and North Korea have all used compromised infrastructure in cyber operations. The strategic question is not who invented the technique.
The evidence in the cited U.S. advisories points to a distinctive Chinese pattern in three respects: the scale of the networks, the use of private Chinese companies as infrastructure providers, and the reported integration of those networks with espionage and critical-infrastructure operations. The April 2026 advisory said Chinese information-security companies had created and maintained covert networks used by China-nexus actors. The FBI’s 2024 advisory similarly described a China-based company controlling a botnet that supported malicious activity. CISA and international partners, FBI, NSA, and CNMF
That does not prove that China is the only state using a service-based model or that every Chinese company named in a government advisory acted under direct state control. It does show that the line between government hacking, private contractors, and criminal-style infrastructure services can be difficult to draw.
The real defense starts at the edge
The QScan and QTRouter case changes the question defenders should ask when they see suspicious traffic.
The first question is no longer simply, “Which foreign server attacked us?” It is also, “Which ordinary device carried the traffic, and who controlled it?”
That requires a more complete inventory of internet-facing equipment, rapid replacement of end-of-life hardware, removal of unnecessary remote administration, strong unique credentials, segmented networks, firmware monitoring, and cooperation among manufacturers, ISPs, security companies, and government agencies. CISA’s 2026 advisory emphasizes that defenders should treat compromised infrastructure as an access vector and should expect covert networks to be updated and reused. CISA and international partners
Manufacturers also bear responsibility. A device that cannot receive security updates for its expected service life becomes a public-risk problem once it is deployed at scale. Secure update mechanisms, clear support periods, vulnerability disclosure programs, and safer default configurations reduce the supply of disposable relays.
The United States cannot eliminate every vulnerable camera, router, or firewall. It can make those devices harder to recruit and less useful after compromise.
The deepest lesson of the QScan and QTRouter disruption is therefore not that every connected object is secretly a spy. It is that foreign intelligence operations increasingly depend on infrastructure nobody thinks of as infrastructure. A router in a home, a camera on a business network, or an appliance in a government facility can become a point in a relay that crosses borders without carrying the attacker’s identity with it.
The device may look domestic. The operation is not.
Sources / References
- U.S. Department of Justice, Office of Public Affairs. “U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure.” January 31, 2024. https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical
- Cybersecurity and Infrastructure Security Agency and international partners. “Defending Against China-Nexus Covert Networks of Compromised Devices.” April 23, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a
- Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force. “People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations.” September 18, 2024. https://www.fbi.gov/file-repository/cyber-alerts/copy_of_peoples-republic-of-china-linked-actors-compromise-routers-and-iot-devices-for-botnet-operations.pdf
- Recorded Future News, The Record. “US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate.” August 26, 2026. https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools
- Nextgov. “FBI disables China-linked hacking tools used against US agencies.” August 26, 2026. https://www.nextgov.com/cybersecurity/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415646/
Continue exploring
Russia's Dawei Bet: A Megaport on the Front Line of Myanmar's Civil War
Russia is backing a deep-sea port on Myanmar's Andaman coast while the army burns villages to clear the land around it, a sign…
17,000 Cracks and a $76 Million Bribe Trail: The Coca Codo Sinclair Reckoning
A Quito court sentenced Lenín Moreno to five years in prison for taking bribes tied to Ecuador's largest hydroelectric plant. The…
How drones, Starlink and covert flights through Chad and Libya are redrawing Sudan's war
What began as a power struggle in Khartoum is now a drone war supplied through Chad and Libya, connected by smuggled satellite…
Comments
No comments yet. Start the conversation below.