DOJ Seizes Two Domains Linked to Chinese State-Sponsored Hacking Group QTFY

The DOJ seized two domains used by Chinese state-sponsored hackers to target U.S. critical infrastructure, including NASA and the Federal Reserve.

DOJ Seizes Two Domains Linked to Chinese State-Sponsored Hacking Group QTFY

Federal Court Authorizes Takedown of Chinese Hacker Infrastructure

A federal judge in San Diego authorized the seizure of two internet domains linked to a Chinese state-sponsored hacking group, the Department of Justice announced Wednesday. According to Courthouse News Service, the domains — QScan and QTRouter — were operated by a group identified as QTFY and used to penetrate critical infrastructure across the United States.

The FBI said in an affidavit supporting the seizures that QTFY created both platforms to scan for vulnerable devices and conceal malicious network traffic. The group has been active since at least 2018, targeting U.S. government agencies including NASA, the Federal Reserve, the Department of Energy, the DOJ itself, and the Senate.

"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," Attorney General Todd Blanche said in the DOJ release. "We are here to ensure security for the American people and will use every tool we have to keep that promise."

How the Platforms Operated

QScan automatically scanned and infected thousands of vulnerable devices worldwide. Those compromised devices were then enrolled into the QTRouter network, forming a botnet — a collection of remotely controlled machines that could be deployed for a range of tasks. In some cases, infected devices were located within the targeted networks themselves, such as on a government employee's computer.

The botnet served primarily to obscure QTFY's actions and mask the Chinese origin of the attacks, the DOJ said. By routing malicious traffic through infected devices, the group made attribution significantly more difficult for investigators.

The DOJ identified QTFY as an entity employed by the Nanjing Xinjiuwei Network Technology Company. Its clients included the Chinese military and China's Ministry of State Security, according to a government advisory also released Wednesday.

Cybersecurity firm Lumen Technologies, which published its own report the same day, described QTFY as operating under a "quartermaster model" — providing the underlying infrastructure to identify targets, route malicious traffic, and obscure its origin for other actors.

Administration Frames Seizure as Cyber Cold War Victory

Trump administration officials cast the domain takedowns as a significant development in an ongoing digital conflict with China. FBI Director Kash Patel said the action aligned directly with the administration's broader cyber posture.

"These tools were used by People's Republic of China cyber actors to hide the origin of their attacks," Patel said. "Today's action is just the latest technical operation against PRC-sponsored hacking — and in support of President Trump's Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace."

The court-ordered seizure rendered both domains inoperable, disabling the QScan and QTRouter infrastructure that depended on them, the DOJ said.

The FBI agent's affidavit also stated there is probable cause to believe the domains were involved in a money laundering scheme, broadening the legal basis for the action beyond cybercrime statutes alone.

"Through complex investigations, aggressive technical operations and strong partnerships, FBI San Diego will continue to identify, disrupt and impose costs on our cyber adversaries," said Mark Remily, Special Agent in Charge of the FBI San Diego Field Office. "We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity."

Part of a Sustained Campaign Against Chinese Hackers

The DOJ described Wednesday's seizures as the latest in a series of technical operations targeting China's state-sponsored hacking activities over the past several years. The Cybersecurity and Infrastructure Security Agency has repeatedly warned that Chinese hackers have embedded themselves in sectors including telecommunications, energy grids, and transportation networks.

The broader conflict between the two countries in cyberspace involves actors on both sides working to gather intelligence and establish footholds in critical systems — a largely invisible competition that occasionally surfaces through enforcement actions like Wednesday's court-authorized domain seizures.

Source: Courthouse News Service