- Key insight: Three of the four victims the affidavit details are financial or insurance firms.
- What's at stake: A bank that runs any of the products named in the advisory has to work out whether those machines were exposed during the years the group was exploiting them, which is a question about historical logs rather than about new attacks.
- Forward look: The seizures made both tools inoperable, but "the Chinese market isn't short on scanning services, so this probably won't deter operations over the medium to long term," according to ETH Zurich researcher Eugenio Benincasa.
Overview bullets generated by AI with editorial review.
The Justice Department and FBI
The details the government shared about the case affect all banks (which are considered critical infrastructure), and especially point to the dangers of not patching software vulnerabilities in a timely manner.
An
Agents seized three domains running QScan, which scanned the internet for vulnerable machines and broke into them; and QTRouter, a network built to disguise where an attack came from.
The FBI, the National Security Agency and the Cyber National Mission Force published a
The advisory lists roughly 390
The government attributes QScan and QTRouter to QTFY, a group employed by Nanjing Xinjiuwei Network Technology Co. that sells hacking services to China's Ministry of State Security and the People's Liberation Army, according to the Justice Department's
The Chinese embassy did not respond to a request for comment from American Banker. A spokesperson
Exploiting unpatched software is now the
The Wednesday advisory said QTFY has used
No bank has been named as a victim in the campaign; the affidavit identifies its victims by pseudonym, and the U.S. has not named any of the 300-plus organizations the threat actors robbed in 2024.
Who got hit
The victims of that 2024 campaign included U.S. defense contractors, financial institutions and universities, according to the
The affidavit documents a selection of four earlier victims (including three financial or insurance firms) that had each complained about suspicious activity. The attackers ran those attacks from servers they leased from Hostwinds, a U.S. hosting company, so all four sent their abuse complaints there.
A financial group in South Korea reported that the released addresses were scanning its network. A financial group in Michigan listed eight of them attacking it over roughly a month. An insurance agency in Missouri reported that it was targeted through a
The fact that three of the four anecdotes in the affidavit related to financial institutions is mostly a reflection of how the sector behaves rather than a sign of a targeted campaign, according to Mark Orsi, chief executive of the Global Resilience Federation and previously a cybersecurity executive at large banks.
Financial institutions "tend to have stronger detection, reporting and information-sharing capabilities which can make them more visible in investigations," Orsi told American Banker.
Another expert was skeptical that the group was targeting the financial sector at all.
"I haven't followed this group, but this does not sound like any major targeting of the finance sector," said Jason Healey, a senior research scholar at Columbia University. Healey previously served as vice chair of the Financial Services Information Sharing and Analysis Center.
What to do with the 390 indicators
While a bank reacting to the Wednesday advisory might instinctively look to block the addresses it lists, that is actually one of the last steps it should take, according to Orsi, the former bank security executive.
An initial review of the indicators "is not a heavy lift for a midsize bank," Orsi said, but someone has to triage the results.
A bank without sufficient staff should route the advisory to its managed security provider or incident-response firm for a sweep of old logs, he advised. This keeps the workload for the bank staff manageable.
Read more:
- These are the
Top Performing Banks of 2026 in four asset tiers - New York bank
regulator says vendor flaw hit its firms - The
best credit unions to work for in 2026 Tokenized deposits are here . Banks need to manage the risks.
If the bank runs any of the products named in the advisory, it should confirm they were patched and work out whether they were exposed during the relevant period, Orsi advised.
Much of that is already automatic, Healey told American Banker. What still takes a person is checking the Chinese companies named in the advisory against the bank's own business relationships, "or on the other side of any deals." A match "should trigger additional investigation," he said.
The advisory lists three key actions: update software and firmware, and audit for equipment past its end of support; stop leaking operational details through internet-facing applications; and isolate critical systems from edge devices. (Edge devices are the firewalls and remote-access gateways that sit between a bank's network and the internet.)
Institutions stall on that third one, according to Orsi. Most large banks should already have that separation "because this has long been a regulatory expectation," and building it later takes "significant investment and a multi-year program."
Institutions often get stuck "because segmentation is treated as a network project without business agreement on which services are truly critical," Orsi said.
Why traditional measures are insufficient
QTRouter existed to make hostile traffic look ordinary, according to the affidavit; it routed the threat actor's activity through a so-called botnet.
A botnet is a collection of everyday devices such as home routers and security cameras that threat actors have quietly compromised, unbeknownst to the everyday consumers who own the devices.
Botnets offer value to threat actors by helping them mask their activity as normal. The traffic from a botnet comes from the homes and offices of regular people who are browsing the internet like normal.
Indeed, the threat actor in this case proxied its own traffic through this botnet, according to
That defeats a set of controls banks use in many other cases: blocking internet traffic based on where it appears to come from.
There is no single tool that reliably teases apart regular traffic from malicious traffic when it comes through a botnet, "so detection relies upon behavior and context," Orsi said.
Large banks generally have the tools for that, but detection still is not guaranteed.
Midsize banks can get meaningful coverage from internal controls plus an outside provider, "but likely not with the same depth" as a large bank, he said.
What a takedown wins banks
The seizures the Justice Department announced Wednesday made QScan and QTRouter "inoperable," according to the
That yielded a disruption, not a total shutdown, according to Adam Hickey, a partner at law firm Mayer Brown who established the Justice Department's national security cyber program.
"It's true that actors can retool, but even that takes some time, so you're disrupting their active hacking activity today," Hickey said.
The seizure also "raises the profile" of the threat actor's methods, "which encourages defenders to develop rules and techniques to detect and prevent" the group's next wave of activity, Hickey told American Banker.
A takedown can probably "dent the market for a while," but not permanently, according to Eugenio Benincasa, a senior cybersecurity researcher at the Center for Security Studies at ETH Zurich. Benincasa studies the Chinese firms that sell these services.
"The Chinese market isn't short on scanning services, so this probably won't deter operations over the medium to long term," said Benincasa.











