
The Justice Department and FBI seized domains tied to two hacking platforms that federal officials say a China-linked cyber group used to target U.S. critical infrastructure and sensitive government networks.
The court-authorized action disrupted QScan and QTRouter. The Justice Department says a People’s Republic of China state-sponsored group known as QTFY created and operated the platforms.
Federal documents allege that China-based Nanjing Xinjiuwei Network Technology Company employs QTFY and that the group sells hacking services to customers including China’s Ministry of State Security and People’s Liberation Army.
Federal records trace QTFY activity to at least 2018. The Justice Department lists NASA, the Federal Reserve, the departments of Energy, Justice and Health and Human Services, the National Institutes of Health and the U.S. Senate among the group’s targets.
DOJ corrects scope of agency breaches
The Justice Department updated its August 26 release on August 28 after initially describing all of the named agencies as victims. The department said the affidavit showed QTFY targeted all of them but compromised only some, Reuters reported.
The affidavit says QTFY actors tried to exploit NASA software in 2019, but the attempt failed because NASA had patched the targeted software. It also alleges that QTFY carried out computer intrusions in September 2024 at three Department of Energy national laboratories, NIH, an HHS agency and a U.S. security-device manufacturer.
The public materials do not identify what information, if any, QTFY obtained from the named federal targets where the government alleges successful intrusions.
A Chinese Embassy spokesperson rejected the accusations and accused the United States of using cybersecurity claims to discredit China, Reuters reported.
Hackers used compromised devices to hide attacks
Federal officials say QScan scans for vulnerable internet-of-things devices and can automatically infect thousands of them worldwide. QTFY then adds compromised devices to QTRouter, which also incorporates commercial proxy services and leased virtual private servers.
QTRouter lets QTFY and other cyber actors route malicious communications through devices outside China and, in some cases, through devices near targeted networks. That setup can conceal the true origin of an intrusion, according to the Justice Department.
The malware depended on hard-coded domains for communication and authentication. The court-authorized seizures took control of key domains and made both QScan and QTRouter inoperable, federal officials said.
Black Lotus Labs, Lumen Technologies’ threat intelligence team, tracked the infrastructure for roughly a year and said it shared threat intelligence with U.S. government agencies and null-routed traffic to known infrastructure points used by the operators.
Federal officials vow continued disruption
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said.
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” FBI Director Kash Patel said.
The FBI, National Security Agency and Cyber National Mission Force also issued a joint cybersecurity advisory detailing QTFY tactics and indicators of compromise. The agencies recommend installing current software and firmware updates, isolating critical systems from edge devices and checking networks for the listed indicators.
The Justice Department also cited earlier operations against PRC-linked cyber activity. The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers in 2025, disabled a Flax Typhoon botnet in 2024 and disrupted a Volt Typhoon botnet in 2023.
As previously reported by The Dallas Express, Texas launched Project Watershed 250 this week to help water and wastewater utilities strengthen defenses against cyber threats from China, Iran and other foreign adversaries.
Provided by Dallas Express









