The Justice Department, together with the FBI, has taken down the online infrastructure of two hacking platforms—QScan and QTRouter—used by a China‑linked cyber group known as QTFY. Federal officials say the group, which is believed to be employed by Nanjing Xinjiuwei Network Technology Company, provides hacking services to China’s Ministry of State Security and the People’s Liberation Army.
National targets and limited intrusions
According to court‑authorized documents, QTFY has been active since at least 2018 and has set its sights on a wide range of U.S. agencies. The Justice Department listed NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health, and the U.S. Senate among the group’s intended victims. While the affidavit indicates attempts on all of these entities, successful compromises were confirmed only at a few locations.
In 2019, QTFY tried to exploit NASA software but was thwarted after the agency applied a patch. More recently, in September 2024, the group allegedly breached three Department of Energy national laboratories, the National Institutes of Health, an HHS agency, and a U.S. security‑device manufacturer. The public record does not disclose what, if any, data was extracted from these intrusions.
How the botnet operated
QScan scans the internet for vulnerable IoT devices and can automatically infect thousands worldwide. Compromised devices are then added to QTRouter, which routes malicious traffic through proxy services and leased virtual private servers, often masking the true origin of attacks. By seizing the hard‑coded domains that the malware relied on for communication and authentication, the DOJ and FBI rendered both platforms inoperable.
Black Lotus Labs, the threat‑intelligence arm of Lumen Technologies, tracked the infrastructure for roughly a year and shared intelligence with U.S. agencies, helping to null‑route traffic to known malicious nodes.
Official response
Attorney General Todd Blanche said, “State‑sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” FBI Director Kash Patel added, “Today we announced the disruption of a global botnet and hacking platform used by Chinese state‑sponsored hackers to target U.S. critical infrastructure.”
The FBI, the National Security Agency and the Cyber National Mission Force also issued a joint advisory urging organizations to install current software and firmware updates, isolate critical systems from edge devices, and scan networks for the indicators of compromise identified in the affidavit.
Broader context
This operation follows previous federal actions against China‑linked cyber activity, including the removal of PlugX surveillance malware from more than 4,000 U.S. computers in 2025 and the disruption of the Volt Typhoon botnet in 2023. In Texas, the state recently launched Project Watershed 250 to bolster water and wastewater utilities against cyber threats from China, Iran and other foreign adversaries.
A Chinese embassy spokesperson dismissed the accusations, claiming the United States is using cybersecurity allegations to tarnish China’s reputation.
Original reporting: The Dallas Express — read the source article.