Justice Department and FBI Seize Domains Behind Chinese Hacking Platforms That Breached NASA, the Fed and the Senate
Federal officials say a Chinese state-sponsored group called QTFY used two hacking tools to infiltrate NASA, the Federal Reserve and the U.S. Senate over at least eight years before investigators traced the operation to a Nanjing company selling access to Beijing's intelligence services.

The Justice Department and the FBI said Wednesday they had seized the internet domains behind two hacking platforms that a Chinese state-sponsored group used for at least eight years to break into the computer networks of NASA, the Federal Reserve, the U.S. Senate and several other federal agencies, part of a broader espionage campaign that officials described as one of the most extensive Chinese hacking operations uncovered against American critical infrastructure.
Court documents unsealed in the Southern District of California identify the group behind the intrusions as "QTFY," which prosecutors say was employed by a Nanjing-based company, Nanjing Xinjiuwei Network Technology Company, and sold hacking services to paying customers including China's Ministry of State Security and the People's Liberation Army. Investigators say the group built and operated two linked tools, known as QScan and QTRouter, that scanned for vulnerable internet-connected devices around the world, silently infected them, and then routed intrusion traffic through the compromised machines to disguise its origin as the group broke into sensitive U.S. networks.
In a statement announcing the seizures, the department said the court-authorized action rendered both platforms inoperable because the seized domains were hard-coded into the malware for essential functions such as communication and authentication with infected devices.
The scope of the intrusions
According to the department, confirmed victims of QTFY's intrusion activity include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate. Officials said the group also targeted hospitals, power companies, telecommunications providers, financial institutions and defense contractors, though it did not name those victims. A vulnerability scan of an unidentified U.S. election system in June and of the Senate in March both failed to gain further access, according to court records.
A joint cybersecurity advisory issued by the FBI and National Security Agency the same day laid out technical indicators of QTFY activity — domain names, IP addresses and file signatures tied to the QTRouter network — that the agencies said stretched back to at least 2018. The advisory was intended to let network defenders at hospitals, utilities and other organizations check whether their own systems had been compromised.
- QScan: described by investigators as an automated scanning and exploitation tool that infected thousands of internet-of-things devices worldwide
- QTRouter: a network of those compromised devices, plus leased virtual servers and commercial proxy services, used to hide the Chinese origin of intrusion traffic
- Confirmed federal victims: NASA, the Federal Reserve, the Energy Department, the Justice Department, HHS, NIH and the U.S. Senate
- Reported timeline of activity: at least 2018 through 2026, according to the unsealed court affidavit
How the operation worked
Prosecutors said QScan and QTRouter functioned together. QScan continuously scanned the internet for vulnerable devices — routers, cameras and other connected hardware — and automatically infected them. Those compromised machines were then folded into the QTRouter network, which investigators called an "obfuscation network" because it let QTFY's traffic appear to originate from ordinary devices scattered around the world, sometimes physically close to the networks being targeted, rather than from China.
The approach mirrors tactics the Justice Department has attributed to other Chinese state-linked hacking groups in recent years. The department noted that in 2025 the FBI removed malware known as PlugX from more than 4,000 U.S. computers infected by a group called Mustang Panda, that in 2024 it disabled a botnet of hundreds of thousands of devices tied to a group called Flax Typhoon, and that in 2023 it disrupted a similar botnet used by a group known as Volt Typhoon to burrow into American critical infrastructure. Officials described Wednesday's action as the latest in that sequence of takedowns.
Independent security researchers corroborated elements of the government's account. Black Lotus Labs, the threat intelligence arm of network operator Lumen Technologies, published its own technical analysis of QTFY's methods alongside the government's announcement, describing the group as functioning like an infrastructure supplier to multiple Chinese hacking teams rather than a single self-contained unit.
Officials frame the takedown as a warning
Attorney General Todd Blanche and FBI Director Kash Patel both spoke to the significance of the action, casting it as part of a wider push against Chinese state-linked hacking rather than a one-off case.
"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise," said Attorney General Todd Blanche.
Patel said the FBI's San Diego field office, its Cyber Division and Justice Department partners had "seized adversary infrastructure and shut these platforms down," calling it part of a broader effort to "shape adversary behavior and defend the homeland in cyberspace." Assistant Attorney General John A. Eisenberg and Southern District of California U.S. Attorney Adam Gordon issued similar statements emphasizing that the seizures were court-authorized and aimed at denying PRC-linked hackers further use of the tools.
A spokesperson for the Chinese Embassy in Washington disputed the allegations, saying Beijing "firmly opposes and combats all forms of cyberattacks in accordance with the law" and urging the United States "to stop using cybersecurity issues to smear or discredit China," according to a CNN report on the department's announcement. Chinese officials have issued similar denials after each of the prior U.S. takedowns of alleged state-linked hacking infrastructure.
Who is affected, and what happens next
None of the agencies named as victims — NASA, the Federal Reserve, the Energy and Health and Human Services departments, NIH or the Senate — issued detailed public statements Wednesday describing what data, if any, the intrusions exposed. The Justice Department's account focuses on network access rather than confirmed data theft, and officials did not say whether any classified or personally identifiable information was taken. The broader set of targets — hospitals, utilities, telecommunications carriers, banks and defense contractors — means the practical reach of the intrusions likely extends well beyond the seven federal agencies named in court papers, though the government has not published a full victim list.
Because QScan indiscriminately infected ordinary internet-connected devices worldwide to build its obfuscation network, the operation's collateral reach touched device owners with no connection to any of the named institutions; the FBI and NSA advisory was aimed partly at helping those device owners and network administrators identify and remove the infections.
Additional reporting on the case notes that the affidavit describes QTFY as including former members of the Chinese military, and that the Nanjing-based company received payments traced to China's Ministry of State Security. No individual defendants have been publicly charged in connection with the seizures, which were filed as civil forfeiture actions against the domains themselves rather than criminal charges against people. The Justice Department said the investigation was led by the FBI's San Diego field office and Cyber Division, together with the U.S. Attorney's Office for the Southern District of California and the National Security Division's National Security Cyber Section, and that it remains open. Officials said they expect to continue identifying and disabling infrastructure tied to QTFY and comparable groups, following the same pattern used against Volt Typhoon, Flax Typhoon and Mustang Panda in prior years — technical disruption first, with any criminal charges, if they come, to follow later.
Flash flooding swamps NYC subways and suspends Staten Island rail service as storms hit five boroughs

False Active-Shooter Report Locks Down East Stroudsburg University in Latest Campus Swatting Case

California Man Arrested After Driving 10-Foot Guillotine to U.S. Capitol
