Last month, the U.S. Department of Justice announced the successful disruption of QScan and QTRouter, two infrastructure platforms operated by Chinese state-sponsored actors and linked to Nanjing Xinjiuwei Network Technology Company. The takedown offers hosting and infrastructure professionals a sobering case study in how threat actors weaponise network infrastructure, and what operators must do to avoid becoming conduits for such activity.
How Platforms Become Attack Infrastructure
QScan and QTRouter were not conventional malware or off-the-shelf exploit kits. They were purpose-built platforms designed to probe networks, identify vulnerabilities, and maintain persistent access to critical infrastructure across the United States. What made them effective was their integration into actual internet-facing systems—likely commodity hosting, VPS instances, or compromised network equipment that the operators could control.
The mechanics are straightforward: threat actors compromise or lease infrastructure, deploy their scanning and command-and-control tooling, and then use that infrastructure to stage attacks against target organisations. From a defender's perspective, the attacker has effectively outsourced their operational footprint to someone else's hosting environment. The hosting provider becomes an unwitting participant in the supply chain of an attack.
Detection Gaps and Operator Responsibility
One critical question emerges: how long did these platforms operate before law enforcement identified them. Weeks. Months. Years. The answer matters because it speaks directly to the detection and response capabilities of the hosting operators who hosted them. According to reporting on the takedown, the infrastructure operated across multiple jurisdictions and network operators. That suggests a distributed footprint—possibly intentional to avoid centralised detection.
Responsible hosting operators maintain network monitoring designed to spot anomalous behaviour: unusual traffic patterns, scanning activity directed outbound, unexpected command-and-control communication. Detecting QScan or QTRouter would have required either automated detection of known signatures or manual investigation of suspicious customer activity. Many providers, especially smaller operations or those running offshore infrastructure, lack the staff or tooling for active threat hunting.
Legal Exposure and Duty of Care
The takedown raises an uncomfortable legal question: what duty does a hosting provider have to detect and report nation-state attack infrastructure running on its servers. U.S. law enforcement clearly identified the responsible operators and took action. But in jurisdictions where hosting providers operate outside active law enforcement partnership, liability becomes murky. A provider harbouring such infrastructure faces potential charges under the Computer Fraud and Abuse Act, regardless of wilful knowledge.
More broadly, organisations that discover their infrastructure is being used for reconnaissance or attacks face pressure to notify affected parties. This intersects with breach notification laws, incident response obligations, and potential liability to downstream victims. A provider that hosts scanning infrastructure without knowing it may still face civil liability if the hosted attack causes harm.
Building Detection Into Operations
For infrastructure operators—whether running datacentres, offering VPS, or managing dedicated servers—the lesson is clear: baseline network monitoring is not optional. Detecting outbound scanning, identifying unusual traffic patterns, and maintaining logs sufficient for forensic analysis should be table stakes. This requires investment in:
- Network telemetry and flow analysis tools that flag scanning and reconnaissance activity
- Incident response procedures that treat suspicious activity as grounds for investigation, not dismissal
- Logging retention policies sufficient to support law enforcement cooperation
- Customer security assessments before onboarding, particularly for sensitive use cases
Smaller operators often lack these capabilities in-house. The solution is not to ignore the problem, but to outsource detection to managed security providers or work with upstream network operators to establish visibility.
Jurisdiction and Cooperation
The successful takedown depended on law enforcement coordination across multiple jurisdictions and hosting providers willing to cooperate with investigations. Operators based in offshore or privacy-focused jurisdictions should recognise that cooperation with law enforcement—when it comes—is not optional. Courts have repeatedly upheld the principle that hosting infrastructure cannot be used as a shield against investigation into serious crimes like critical infrastructure attacks.
Operating offshore or accepting cryptocurrency payments does not exempt a provider from the responsibility to maintain secure infrastructure. State-sponsored attacks on critical infrastructure represent a threshold above routine law enforcement concerns. Hosting providers that knowingly or negligently host such infrastructure face both criminal and civil exposure.
The disruption of QTFY's infrastructure demonstrates that law enforcement has the technical sophistication to identify and act against distributed attack platforms. Hosting operators who treat security as a cost rather than a core operational requirement are gambling that their customers are uninteresting to state actors—a bet that grows riskier each year.

