The Your
Sep 02, 2026
HyperLocal Loop
The Your

Close to home. Always in the loop.

DOJ and FBI Disrupt China‑Linked Botnet Targeting NASA, Senate and Federal Agencies

The Justice Department, together with the FBI, has taken down the online infrastructure of two hacking platforms—QScan and QTRouter—used by a China‑linked cyber group known as QTFY. Federal officials say the group, which is believed to be employed by Nanjing Xinjiuwei Network Technology Company, provides hacking services to China’s Ministry of State Security and the People’s Liberation Army.

National targets and limited intrusions

According to court‑authorized documents, QTFY has been active since at least 2018 and has set its sights on a wide range of U.S. agencies. The Justice Department listed NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health, and the U.S. Senate among the group’s intended victims. While the affidavit indicates attempts on all of these entities, successful compromises were confirmed only at a few locations.

In 2019, QTFY tried to exploit NASA software but was thwarted after the agency applied a patch. More recently, in September 2024, the group allegedly breached three Department of Energy national laboratories, the National Institutes of Health, an HHS agency, and a U.S. security‑device manufacturer. The public record does not disclose what, if any, data was extracted from these intrusions.

How the botnet operated

QScan scans the internet for vulnerable IoT devices and can automatically infect thousands worldwide. Compromised devices are then added to QTRouter, which routes malicious traffic through proxy services and leased virtual private servers, often masking the true origin of attacks. By seizing the hard‑coded domains that the malware relied on for communication and authentication, the DOJ and FBI rendered both platforms inoperable.

Black Lotus Labs, the threat‑intelligence arm of Lumen Technologies, tracked the infrastructure for roughly a year and shared intelligence with U.S. agencies, helping to null‑route traffic to known malicious nodes.

Official response

Attorney General Todd Blanche said, “State‑sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” FBI Director Kash Patel added, “Today we announced the disruption of a global botnet and hacking platform used by Chinese state‑sponsored hackers to target U.S. critical infrastructure.”

The FBI, the National Security Agency and the Cyber National Mission Force also issued a joint advisory urging organizations to install current software and firmware updates, isolate critical systems from edge devices, and scan networks for the indicators of compromise identified in the affidavit.

Broader context

This operation follows previous federal actions against China‑linked cyber activity, including the removal of PlugX surveillance malware from more than 4,000 U.S. computers in 2025 and the disruption of the Volt Typhoon botnet in 2023. In Texas, the state recently launched Project Watershed 250 to bolster water and wastewater utilities against cyber threats from China, Iran and other foreign adversaries.

A Chinese embassy spokesperson dismissed the accusations, claiming the United States is using cybersecurity allegations to tarnish China’s reputation.


Original reporting: The Dallas Express — read the source article.

OBBM Network Editorial Staff

[email protected]

Editorial team behind OBBM Network — independent, hyper-local journalism syndicated through HyperLocalLoop and OBBM Network TV.

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent News

Trending

Community News

Quick Start Deal

Get Loop-Ready in One Move

A low-commitment monthly bundle that keeps your business in front of local audiences across HyperLocal Loop and the OBBM Network.

$350 Per Month
What's Included
  • DataPulse · 1,000 Matches Identify and retarget anonymous visitors to your site
  • Banner Ads Geo-targeted display placement across HyperLocal Loop
  • Video Ad Airs on your Local OBBM Channel
  • Business Advertorial A featured sponsored article telling your story
Questions about any of this? Ask Ben →
Get Started
Secure checkout · Cancel anytime
§ 04 · Choose Your Package

Three levels. Up to 60% off.

Every Patriot Package is priced at over 40% off standard AdRevv list rates — and the discount deepens as you scale, up to 60% off at the Enterprise tier.

Tier I · Local
The Patriot
For local & regional brands launching with the network.
List Price: $835/mo
$500/mo
★ Save $335 — 40% Off
Monthly Allotment
  • Audio: 10,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 50,000HyperLocal Loop geo-targeted banner impressions
  • DataPulse: First 1,000visitor matches included
  • City or regional geo-targeting via AdServe
  • Real-time campaign reporting
Start The Patriot
Tier III · National
The Enterprise
For national brands ready to dominate the network.
List Price: $5,065/mo
$2026/mo
★ Save $3,039 — 60% Off
Monthly Allotment
  • Audio: 14,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 100,000HyperLocal Loop geo-targeted impressions
  • DataPulse: 5,000visitor matches included
  • LeadEngine: 20,000actionable buyer-intent contacts
  • Host Endorsements: 9podcast host-read spots
  • National geo-targeting + dedicated campaign manager
  • Priority creative production support
★ Bonus Included
Free 1-Year Freedom Chamber Membership
Faith, Family & Freedom business community at freedomchamber.net.
Start Enterprise

Need a custom configuration? Build your own package →