Voice of America (public domain) · source
Composite story
U.S. seizes China-linked hacking platforms, then narrows who was breached
The Justice Department and FBI seized QScan and QTRouter domains used by China-linked group QTFY. Days later DOJ said named agencies were targets, and that only some were compromised.
On Wednesday the Justice Department and FBI announced court-authorized seizures of domains for QScan and QTRouter, platforms they say China-linked group QTFY ran through Nanjing Xinjiuwei Network Technology for clients including the Ministry of State Security and the PLA. An FBI affidavit described a campaign since at least 2018. On Friday DOJ edited its release to say NASA, the Fed, the Senate and other agencies were among the targets, and that the original text had treated all of them as victims when the affidavit said only some were compromised. The affidavit says a 2019 NASA attempt failed because software had been patched, and that September 2024 intrusions hit three Energy Department labs, NIH, an HHS agency, and a U.S. security-device maker.
US officials revise claims that government agencies were hacked by Chinese, now say they were targets
28 Aug 2026
Facts
U.S. officials are correcting earlier statements that several government agencies were hacked by Chinese hackers.
A previous version of the statement said the agencies had been among the hackers' victims.
DOJ described a years-long Chinese cyber-espionage campaign against U.S. agencies, defense contractors and other sensitive targets.
The advisory listed successful May 2024 data thefts from unnamed defense contractors, financial institutions and universities.
The advisory listed an unsuccessful March 2026 attempt to access a U.S. hospital network.
The spokesperson said China opposes using national security as a pretext for discriminatory restrictions on Chinese companies.
The FBI and CISA did not immediately return messages seeking clarification on Friday.
The Chinese Embassy in Washington did not immediately respond on Friday.
Opinion
The distinction matters because it narrows the scope of confirmed breaches.
US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies
26 Aug 2026
Facts
Four unnamed companies in the US and South Korea were also identified as targets.
The seizures disrupt access to the platforms but do not mean all of the group's activity has been eliminated.
Richard Hummel of SecurityScorecard said a local-looking intrusion buys the operator time and slows attribution.
Neither the Chinese embassy nor Nanjing Xinjiuwei responded to Reuters questions.
Hummel said taking the two platforms offline costs operators capability they used every day.
In March the FBI told Congress hackers had penetrated certain agency networks related to people under FBI investigation.
Chinese-linked hackers have been tied to House committee networks and major telecommunications companies.
Opinion
No opinion marked.
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
27 Aug 2026
Facts
The seizures cut off access to malware that had been used against U.S. government agencies for years.
QScan and QTRouter worked as a pair.
Opinion
FBI Director Kash Patel framed the takedown as part of a broader push against Chinese-linked cyber operations.
DOJ blames China for string of hacks targeting federal agencies and hospitals
26 Aug 2026
Facts
The group was used to attack networks at U.S. agencies, hospitals, power companies and financial institutions.
The affidavit said U.S. Senate systems were targeted this year.
QTFY tried at least twice, in 2019 and in June, to find vulnerabilities in unnamed U.S. election systems.
The September 2024 compromises used a zero-day vulnerability.
HHS' Health Resources and Services Administration was among the September 2024 compromises.
The group successfully installed malware in Taiwanese energy systems in 2021.
In 2021 the group used a common vulnerability to access an unnamed U.S. state government and a large U.S. retail company.
The advisory said many breaches were to gain and maintain access to critical U.S. networks.
A person familiar said a 2019 Federal Reserve incident was of limited scope and the Fed worked with the FBI.
DOJ, NIH, Energy, and the Senate Sergeant at Arms did not comment on the breaches.
Chinese President Xi Jinping is scheduled to visit Washington next month.
NASA said it does not comment on specific reports of potential vulnerabilities or incidents.
In 2023, officials said Volt Typhoon had attacked U.S. mainland and Guam-related organizations since 2021.
After a May trip, Trump said he discussed Chinese-linked cyberattacks with Xi and that the U.S. is spying like hell on China in response.
HHS and Federal Reserve spokespeople declined to comment.
Chinese officials described Trump and Vance device-hack reports as disinformation.
In 2024 Salt Typhoon was accused of breaching U.S. telecom systems and devices of Trump and Vance.
CISA did not comment on how the federal government is responding.
Chinese hackers gained access to emails of top Biden officials at Commerce and State in 2023.
Opinion
Cybersecurity officials described Volt Typhoon as comparable to a cyber invasion by China.
Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
26 Aug 2026
Facts
The platforms QScan and QTRouter were used to target U.S. critical infrastructure and other sensitive networks.
FBI Director Kash Patel said they disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers.
Court documents were unsealed in the Southern District of California.
Patel said they seized adversary infrastructure and shut the platforms down.
Patel said the action supports President Trump’s Cyber Strategy for America.
AAG John A. Eisenberg said DOJ is going on the offensive against cyber threats to national security.
FBI San Diego SAC Mark Remily said the FBI remains relentless against nation-state cyber actors.
Opinion
No opinion marked.
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
27 Aug 2026
Facts
Court documents say MSS payments to Nanjing Xinjiuwei indicate the company conducts malicious cyber activity for the PRC government.
QTFY also operated botnets of compromised IoT devices.
Court documents say QTFY actors include former PLA members who use those ties to get offensive-cyber contracts.
On Monday a U.S. court granted seizure warrants for qtproxy.xyz, qt-proxy.org, and qt-team.com.
QTRouter also lets other paying criminals conceal the origin of their intrusions.
The attempt tried to exploit CVE-2019-11510 in Ivanti Pulse Secure VPN.
CVE-2019-11510 allowed attackers to learn legitimate users' usernames and passwords.
Ivanti patched the flaw in April 2019.
Court documents say those entities were victims of an Ivanti Cloud Services Appliance zero-day.
Other 2019-2020 victims included unnamed financial groups in Michigan and South Korea and a Missouri insurance agency.
The Missouri insurance attack used CVE-2019-19781 in Citrix VPN products.
The Register said China previously abused this bug as a zero-day against defense, government, and finance organizations.
CVE-2019-19781 allowed arbitrary code execution with no account credentials.
The Register said Flax Typhoon burned down its own botnet of hundreds of thousands of IoT devices when confronted by U.S. authorities.
The FBI did not respond to The Register’s questions about compromise counts or Typhoon-group ties.
In June Lumen reported a Volt Typhoon-linked botnet resurgence to about 1,500 compromised routers and IoT devices.
Opinion
The Register called the operators Chinese government snoops.
The Register said the seizures were intended to hamstring China’s hacking activities.
