Spunzo

The Un-Spun Zone.

The Robert F. Kennedy Department of Justice Building in Washington.
The Robert F. Kennedy Department of Justice Building in Washington.

Voice of America (public domain) · source

Composite story

U.S. seizes China-linked hacking platforms, then narrows who was breached

The Justice Department and FBI seized QScan and QTRouter domains used by China-linked group QTFY. Days later DOJ said named agencies were targets, and that only some were compromised.

On Wednesday the Justice Department and FBI announced court-authorized seizures of domains for QScan and QTRouter, platforms they say China-linked group QTFY ran through Nanjing Xinjiuwei Network Technology for clients including the Ministry of State Security and the PLA. An FBI affidavit described a campaign since at least 2018. On Friday DOJ edited its release to say NASA, the Fed, the Senate and other agencies were among the targets, and that the original text had treated all of them as victims when the affidavit said only some were compromised. The affidavit says a 2019 NASA attempt failed because software had been patched, and that September 2024 intrusions hit three Energy Department labs, NIH, an HHS agency, and a U.S. security-device maker.

Shared facts

The FBI said Wednesday it disrupted a botnet and seized two platforms.

Among QTFY's targets are NASA, the Federal Reserve, Energy, Justice, HHS, NIH, and the U.S. Senate.

QScan is vulnerability-scanning and exploitation malware, and QTRouter is an obfuscation network.

The FBI says PRC-backed group QTFY created and operated the two platforms.

The FBI says QTFY’s hackers work for Nanjing Xinjiuwei.

In 2024 QTFY broke into three DOE labs, NIH, and a US security-device manufacturer.

The services have been in use since at least 2018.

The FBI investigated an attempted NASA intrusion in August 2019.

QTRouter is an obfuscation network of compromised IoT devices, commercial proxies, and leased servers.

Customers include China’s Ministry of State Security and the People’s Liberation Army.

Court documents say QTFY offers hacking services to paying customers including the MSS and PLA.

QScan scans and infects thousands of IoT devices and adds them to QTRouter.

DOJ said edits were made so the release accurately reflects the affidavit's allegations.

DOJ said the hardcoded-domain seizures made both hacking services inoperable.

Attorney General Todd Blanche said state-sponsored hackers preying on America’s critical infrastructure will be stopped and prosecuted.

Patel said the tools were used by PRC cyber actors to hide the origin of their attacks.

QTFY exploited the same CVE in 2020 to attack an Ohio medical center.

Blanche said federal law enforcement investigated and disabled the PRC’s malicious software.

The FBI and NSA published a QTFY cybersecurity advisory based on activity dating back to at least 2018.

QTRouter conceals the PRC origin of intrusions so traffic can appear to come from outside China or near the target.

This is the latest in a series of operations against PRC hacking activities.

U.S. Attorney Adam Gordon said they are taking the fight to PRC-sponsored cybercriminals.

A Chinese Embassy spokesperson said China opposes cyberattacks and urged the U.S. to stop using cybersecurity to smear China.

In 2025 the FBI removed PlugX from more than 4,000 US computers infected by Mustang Panda.

In 2024 the FBI disabled a Flax Typhoon botnet of hundreds of thousands of infected IoT devices.

In late 2023 the FBI disrupted a Volt Typhoon botnet used against US and foreign critical infrastructure.

FBI San Diego, the Southern District of California, and DOJ's National Security Division led the investigation.

Lumen's Black Lotus Labs published a description of QTFY's tactics.

Disputed facts

The Register said the Fed, DOJ, HHS, and NIH were among those victimized.

Court documents say QTFY infrastructure compromised the US Senate this year.

Reuters

US officials revise claims that government agencies were hacked by Chinese, now say they were targets

Raphael Satter and AJ Vicens

28 Aug 2026

Facts

U.S. officials are correcting earlier statements that several government agencies were hacked by Chinese hackers.

A previous version of the statement said the agencies had been among the hackers' victims.

DOJ described a years-long Chinese cyber-espionage campaign against U.S. agencies, defense contractors and other sensitive targets.

The advisory listed successful May 2024 data thefts from unnamed defense contractors, financial institutions and universities.

The advisory listed an unsuccessful March 2026 attempt to access a U.S. hospital network.

The spokesperson said China opposes using national security as a pretext for discriminatory restrictions on Chinese companies.

The FBI and CISA did not immediately return messages seeking clarification on Friday.

The Chinese Embassy in Washington did not immediately respond on Friday.

Opinion

The distinction matters because it narrows the scope of confirmed breaches.

Al Jazeera

US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

Catherine Nouhan and Reuters

26 Aug 2026

Facts

Four unnamed companies in the US and South Korea were also identified as targets.

The seizures disrupt access to the platforms but do not mean all of the group's activity has been eliminated.

Richard Hummel of SecurityScorecard said a local-looking intrusion buys the operator time and slows attribution.

Neither the Chinese embassy nor Nanjing Xinjiuwei responded to Reuters questions.

Hummel said taking the two platforms offline costs operators capability they used every day.

In March the FBI told Congress hackers had penetrated certain agency networks related to people under FBI investigation.

Chinese-linked hackers have been tied to House committee networks and major telecommunications companies.

Opinion

No opinion marked.

Help Net Security

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate

Sinisa Markovic

27 Aug 2026

Facts

The seizures cut off access to malware that had been used against U.S. government agencies for years.

QScan and QTRouter worked as a pair.

Opinion

FBI Director Kash Patel framed the takedown as part of a broader push against Chinese-linked cyber operations.

POLITICO

DOJ blames China for string of hacks targeting federal agencies and hospitals

Maggie Miller

26 Aug 2026

Facts

The group was used to attack networks at U.S. agencies, hospitals, power companies and financial institutions.

The affidavit said U.S. Senate systems were targeted this year.

QTFY tried at least twice, in 2019 and in June, to find vulnerabilities in unnamed U.S. election systems.

The September 2024 compromises used a zero-day vulnerability.

HHS' Health Resources and Services Administration was among the September 2024 compromises.

The group successfully installed malware in Taiwanese energy systems in 2021.

In 2021 the group used a common vulnerability to access an unnamed U.S. state government and a large U.S. retail company.

The advisory said many breaches were to gain and maintain access to critical U.S. networks.

A person familiar said a 2019 Federal Reserve incident was of limited scope and the Fed worked with the FBI.

DOJ, NIH, Energy, and the Senate Sergeant at Arms did not comment on the breaches.

Chinese President Xi Jinping is scheduled to visit Washington next month.

NASA said it does not comment on specific reports of potential vulnerabilities or incidents.

In 2023, officials said Volt Typhoon had attacked U.S. mainland and Guam-related organizations since 2021.

After a May trip, Trump said he discussed Chinese-linked cyberattacks with Xi and that the U.S. is spying like hell on China in response.

HHS and Federal Reserve spokespeople declined to comment.

Chinese officials described Trump and Vance device-hack reports as disinformation.

In 2024 Salt Typhoon was accused of breaching U.S. telecom systems and devices of Trump and Vance.

CISA did not comment on how the federal government is responding.

Chinese hackers gained access to emails of top Biden officials at Commerce and State in 2023.

Opinion

Cybersecurity officials described Volt Typhoon as comparable to a cyber invasion by China.

U.S. Department of Justice

Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

Office of Public Affairs

26 Aug 2026

Facts

The platforms QScan and QTRouter were used to target U.S. critical infrastructure and other sensitive networks.

FBI Director Kash Patel said they disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers.

Court documents were unsealed in the Southern District of California.

Patel said they seized adversary infrastructure and shut the platforms down.

Patel said the action supports President Trump’s Cyber Strategy for America.

AAG John A. Eisenberg said DOJ is going on the offensive against cyber threats to national security.

FBI San Diego SAC Mark Remily said the FBI remains relentless against nation-state cyber actors.

Opinion

No opinion marked.

The Register

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

Jessica Lyons

27 Aug 2026

Facts

Court documents say MSS payments to Nanjing Xinjiuwei indicate the company conducts malicious cyber activity for the PRC government.

QTFY also operated botnets of compromised IoT devices.

Court documents say QTFY actors include former PLA members who use those ties to get offensive-cyber contracts.

On Monday a U.S. court granted seizure warrants for qtproxy.xyz, qt-proxy.org, and qt-team.com.

QTRouter also lets other paying criminals conceal the origin of their intrusions.

The attempt tried to exploit CVE-2019-11510 in Ivanti Pulse Secure VPN.

CVE-2019-11510 allowed attackers to learn legitimate users' usernames and passwords.

Ivanti patched the flaw in April 2019.

Court documents say those entities were victims of an Ivanti Cloud Services Appliance zero-day.

Other 2019-2020 victims included unnamed financial groups in Michigan and South Korea and a Missouri insurance agency.

The Missouri insurance attack used CVE-2019-19781 in Citrix VPN products.

The Register said China previously abused this bug as a zero-day against defense, government, and finance organizations.

CVE-2019-19781 allowed arbitrary code execution with no account credentials.

The Register said Flax Typhoon burned down its own botnet of hundreds of thousands of IoT devices when confronted by U.S. authorities.

The FBI did not respond to The Register’s questions about compromise counts or Typhoon-group ties.

In June Lumen reported a Volt Typhoon-linked botnet resurgence to about 1,500 compromised routers and IoT devices.

Opinion

The Register called the operators Chinese government snoops.

The Register said the seizures were intended to hamstring China’s hacking activities.