DOJ and FBI Seize Chinese State-Sponsored Hacking Platforms Targeting U.S. Infrastructure
U.S. authorities seized domains of two Chinese hacking platforms, "QScan" and "QTRouter," used to attack NASA, the Federal Reserve, and other critical networks.

FBI and DOJ Shut Down China-Linked Hacking Tools Used Against NASA, Federal Reserve, and Senate
The Justice Department and the FBI have seized the domains of two interconnected hacking platforms — "QScan" and "QTRouter" — used by a Chinese state-sponsored group to infiltrate U.S. critical infrastructure, DOJ Justice News reported. The court-authorized seizures were filed in the Southern District of California.
According to unsealed court documents, the platforms were created and operated by a group known as "QTFY," employed by the China-based firm Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). Among the confirmed targets are the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
How the Two Platforms Worked Together
QScan and QTRouter functioned as complementary tools. QScan automatically scanned for and infected thousands of internet-of-things (IoT) devices worldwide, adding them to a network of QTFY-controlled machines. QTRouter then used those compromised devices — along with commercial proxy services and leased virtual private servers — as an obfuscation network.
The effect was to disguise the Chinese origin of intrusion activity. Malicious traffic appeared to come from devices located outside the People's Republic of China, sometimes even from computers local to the targeted networks. Because the seized domains were hard-coded into both malware strains and used for essential functions such as communication and authentication, the seizures rendered both platforms inoperable.
Court documents further indicate that QTFY offered these hacking services to paying customers, including the PRC's Ministry of State Security and the People's Liberation Army.
Officials Describe an Escalating Offensive Posture
Attorney General Todd Blanche said federal law enforcement had "investigated and disabled the PRC's malicious software," calling it "the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China."
FBI Director Kash Patel described the action as the disruption of "a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," crediting the FBI's San Diego Field Office, its Cyber Division, and DOJ partners. Patel added that the operation was consistent with President Trump's Cyber Strategy for America and that "the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace."
Assistant Attorney General for National Security John A. Eisenberg called the seizures evidence of the Justice Department's "steadfast commitment to going on the offensive against cyber threats to the national security." U.S. Attorney Adam Gordon for the Southern District of California said authorities were "taking the fight to PRC sponsored cybercriminals to protect the critical services Americans rely on every day."
Special Agent in Charge Mark Remily of the FBI San Diego Field Office emphasized that the bureau would "continue to identify, disrupt, and impose costs on our cyber adversaries" through what he described as "complex investigations, aggressive technical operations, and strong partnerships."
Part of a Broader Pattern of Disruptions
Tuesday's action is one of several court-authorized technical operations the U.S. government has conducted against PRC-linked hacking infrastructure in recent years.
In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers following infections attributed to the PRC-sponsored group Mustang Panda. In 2024, agents disabled a botnet of hundreds of thousands of infected IoT devices that the group Flax Typhoon had been providing to customers in the Chinese government. In 2023, a separate botnet used by Volt Typhoon — another PRC-sponsored group — was disrupted after the hackers used it to conceal attacks on U.S. and foreign critical infrastructure.
Also on the day of the current announcement, the FBI and the National Security Agency published a joint cybersecurity advisory providing indicators of compromise based on analysis of QTFY activity dating back to at least 2018. Lumen Technologies' threat intelligence unit, Black Lotus Labs, simultaneously released a technical report describing QTFY's tactics, techniques, and procedures.
The investigation was led by the FBI San Diego Field Office, the FBI Cyber Division, the U.S. Attorney's Office for the Southern District of California, and the National Security Cyber Section of the Justice Department's National Security Division.
Source: DOJ Justice News