“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Attorney General Todd Blanche statted. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
DOJ action: court-authorized seizures of QScan and QTRouter
The Department of Justice announced court-authorized domain seizures of two named hacking platforms, “QScan” and “QTRouter,” saying the action blocked access by malicious actors. The DOJ framed the technical operations as a law enforcement response to reported targeting of U.S. critical infrastructure and described the seizures as part of a broader effort to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.
Targets named in the report: federal agencies and institutions
The source lists multiple federal entities that were targeted by a Chinese state-sponsored actor, including:
- The Department of Justice (DOJ)
- The U.S. Senate
- The Federal Reserve
- NASA
- The Energy Department
- The Health and Human Services Department
- The National Institutes of Health
- Other federal entities
The DOJ described the campaign in the context of threats to critical infrastructure and said law enforcement disabled the PRC’s malicious software through the court-authorized seizures.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMonzy Merza: hospitals, under-resourced organizations, and sovereign AI
Monzy Merza, co-founder and CEO of Crogl, used the incident to highlight resource disparities between large federal targets and smaller institutions. “This news highlights the need for sophisticated defensive capabilities for less resourced organizations like hospitals and critical infrastructure. And it strengthens the argument for sovereign AI capabilities as organizations look to improve their security postures in the face of continually evolving advanced threats. It’s also cautionary for AI driven security vendors whose pricing models charge based on investigations.
“Security teams need to investigate more, hunt more, and need easy access to AI technologies for cyber defense. This article really showcases the asymmetry: the teams who are the most under resourced and have the biggest need are often the ones that have the hardest time getting access to AI resources.”
Jake Williams: prepositioning, parity, and the Internet’s asymmetry
Jake Williams, identified as a former NSA hacker and current faculty at IANS Research, framed the event as consistent with established nation-state tradecraft while warning about double standards in rhetoric. “Nothing in this report is particularly surprising or even out of the norm: It's a dangerous and slippery slope to say things like ‘contractor working at the behest of the Chinese government.’ You could easily substitute ‘Nanjing Xinjiuwei Network Technology Company’ for ‘Lockheed Martin’ and make this a story about a U.S. company enabling hacking for the U.S. How would we react if the Chinese government seized a U.S. contractor domain? They don’t have that capability, but that’s only because the U.S. overall runs the Internet (nobody likes to admit that, but it really is the U.S.).
“Nation state threat actors need prepositioning to deliver cyber effects at the time of need. Extensive prepositioning, especially in security blind spots like IoT devices, should be expected as the new norm.”
What this means for hospitals, security teams, and AI-driven security vendors
- Hospitals and less resourced critical infrastructure: Merza’s comments make clear these organizations will be pointedly concerned about access to advanced defensive tools and sovereign AI capabilities, as they are named examples of entities with acute need but limited means.
- Security teams and incident responders: The DOJ’s technical seizures demonstrate one law-enforcement approach to disrupting malware platforms, while Merza’s and Williams’s observations underscore pressure on defenders to “investigate more, hunt more,” and to harden blind spots such as IoT where prepositioning can occur.
- AI-driven security vendors: Merza explicitly flagged pricing models that bill per investigation as “cautionary,” suggesting procurement leaders and defenders will watch vendor economics as closely as capabilities when acquiring AI tools for cyber defense.
The DOJ’s public characterization — that federal law enforcement “investigated and disabled the PRC’s malicious software” through court-authorized domain seizures of QScan and QTRouter — is the tangible outcome reported. Experts quoted in the coverage frame the operation as necessary but insufficient on its own: they say the incident highlights persistent asymmetries in resources, the growing importance of AI access for defenders, and the continued likelihood of nation-state prepositioning in security blind spots such as IoT.




