The disrupted systems were known as QScan and QTRouter. An FBI affidavit says the group running the platforms, QTFY, works for the private Chinese company Nanjing Xinjiuwei Network Technology.

QScan and QTRouter are just two components of a complex system, but both used hard-coded domains, making them susceptible to court-authorized domain seizures.

Qscan was a distributed vulnerability scanning system that was used to find and scan target networks plus identify vulnerable Internet of Things (IoT) devices that could be co-opted into QTFY’s various botnets. An FBI/National Security Agency joint cybersecurity advisory says that Qscan populates a QTFY database containing nearly a decade’s worth of internet scanning. This database is used when targeting a specific victim or to quickly identify targets of interest when new vulnerabilities are discovered.

QTRouter was a covert communications platform to obfuscate the Chinese origin of traffic. Malicious traffic would be routed through compromised IoT devices.