
Federal authorities say they have disabled two online tools connected to a Chinese hacking operation that went after American government agencies and other sensitive computer systems. The Justice Department and FBI announced Wednesday that they had taken control of internet domains needed by QScan and QTRouter, two platforms investigators say were operated by a group called QTFY.
The investigation involved attempted or successful intrusions across a wide range of federal organizations. Among the agencies named were NASA, the Federal Reserve, Justice Department, Energy Department, Department of Health and Human Services and National Institutes of Health. The U.S. Senate was targeted too.
QTFY is tied by U.S. investigators to Nanjing Xinjiuwei Network Technology Company, a business located in China. Authorities say the company had Chinese government customers, including the country’s civilian intelligence service and military. The activity examined by investigators reaches back to at least 2018.
QScan was basically the part of the operation that searched for equipment the hackers could take over. It looked across the internet for vulnerable connected devices, including routers, and infected them when possible. This eventually gave the operators access to thousands of devices located in different parts of the world.
Those infected machines could then be used by QTRouter. The second platform combined compromised equipment with rented servers and devices associated with commercial proxy services, creating a network that could pass internet traffic through different locations before it reached a target.
That made the location of the attacker much less obvious. Someone operating from China could send activity through an infected machine elsewhere, causing the traffic seen by a victim to appear as if it started in another country. It might even seem to be coming from somewhere near the organization being attacked.
The devices caught up in the network were not necessarily owned by people involved in the operation. A regular internet-connected device that had been compromised could become one piece of the system and help carry traffic without its owner realizing what was happening.
Investigators found a weakness in how the two platforms operated. Certain internet domains were built into the malicious software and were needed for the system to communicate and verify access. Federal officials received court permission to take control of those domains, leaving QScan and QTRouter without resources they needed to keep operating.
Court records describe several incidents connected to the investigation. In August 2019, hackers tried to enter NASA’s network but did not succeed. By September 2024, other attacks had gotten further, with networks at three Energy Department laboratories among those breached.
Systems connected to NIH and HHS were also entered during that period, according to the records. Investigators identified a U.S. manufacturer of security equipment as another organization that was successfully attacked. The Federal Reserve and Senate appear in the documents as targets, along with four companies in the United States and South Korea whose names were not released.
Attorney General Todd Blanche said the federal government intends to continue pursuing state-backed hackers who threaten American infrastructure. FBI Director Kash Patel said QScan and QTRouter gave Chinese cyber actors a way to make the real starting point of their activity difficult to see.
Officials also described QTFY as a provider of cyber services rather than only a hacking group acting on its own. The Chinese Ministry of State Security and People’s Liberation Army were identified in the court material as customers. Investigators also said former members of the Chinese military worked for the Nanjing company and had connections that helped with obtaining cyber work.
China rejected the accusation that its government supports this kind of hacking. A Chinese Embassy spokesperson in Washington said the country opposes cyberattacks and accused the United States of using cybersecurity claims to damage China’s reputation. The company connected to QTFY did not provide a response to requests for comment mentioned in the supplied reports.
The FBI has carried out several other operations against cyber networks that U.S. officials have associated with Chinese groups. One came in 2023, when authorities interfered with a collection of compromised devices being used by Volt Typhoon to disguise activity involving infrastructure in the United States and abroad.
Another large network was taken down the following year. That one contained hundreds of thousands of infected internet-connected devices and was associated by authorities with Flax Typhoon. Investigators said customers connected to the Chinese government had access to the network.
Federal authorities targeted a different form of malicious software in 2025. That operation focused on PlugX, surveillance software associated with Mustang Panda. Rather than describing it as a network takedown, officials said the FBI cleaned the malware from thousands of machines located across the United States, with the total exceeding 4,000.
The latest action was accompanied by new information for cybersecurity workers. The FBI and National Security Agency released an advisory containing clues that organizations can look for when checking their systems for activity associated with QTFY. That information came from analysis covering years of the group’s activity.
Black Lotus Labs, part of Lumen Technologies, also released research describing the operation’s methods and infrastructure. Its work examined how the network was constructed and how the people behind it could use ordinary-looking internet traffic as cover for their activity.
The FBI’s San Diego Field Office and Cyber Division worked on the case with federal prosecutors in Southern California and the Justice Department’s National Security Division. Their investigation eventually led authorities to the domains supporting QScan and QTRouter, which gave the government a way to interfere directly with the systems rather than only identify the people and organizations believed to be behind them.
This image is the property of The New Dispatch LLC and is not licenseable for external use without explicit written permission.







