FBI and DOJ Seize China-Linked Hacking Platforms Used Against NASA, Justice, the Fed, and the Senate
The FBI and Justice Department seized three domains that disabled China-linked hacking platforms used against NASA, the Federal Reserve, the Justice Department, and the U.S. Senate.

The Justice Department and FBI announced Wednesday they seized internet domains used by two complementary hacking platforms that prosecutors say were built and operated by a People’s Republic of China state-sponsored group and used against U.S. government networks, including NASA, the Federal Reserve, the Department of Justice, and the U.S. Senate.
Court-authorized warrants in the Southern District of California targeted three domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—hard-coded into malware known as QScan and QTRouter. Officials said those domains handled communication and authentication for both platforms and that seizing them rendered the tools inoperable. The announcement was dated Aug. 26. The warrants were granted earlier in the week.
Unsealed court documents identify the operators as a group tracked as QTFY, employed by Nanjing Xinjiuwei Network Technology Company, a China-based firm established in 2018. Prosecutors said QTFY sold hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. Payments from the Ministry of State Security to the company, the filings said, indicate the firm conducted malicious cyber activity on behalf of the PRC government.
The Justice Department listed among the victims of QTFY intrusion activity NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. An FBI affidavit described a campaign dating to at least 2018 against U.S. and foreign networks. Not every attempt succeeded. Court papers described an unsuccessful August 2019 effort against NASA networks that targeted a VPN flaw, and unsuccessful March 2026 attempts against Senate networks and a U.S. hospital. The same filings described September 2024 intrusions at three unnamed Energy Department laboratories, NIH, an unnamed HHS agency, and a U.S. security-device manufacturer, and said QTFY exploited a Check Point equipment flaw in May 2024, stealing server settings and account information from more than 300 U.S. organizations. Four unnamed companies in the United States and South Korea were also identified as victims.
QScan scanned the internet for exposed systems, automatically infected thousands of internet-of-things devices, and maintained a library of more than 200 proof-of-concept exploits. Investigators said the platform processed more than 2 million scanning or exploitation tasks on a single day in 2024. Compromised devices were folded into QTRouter, which also used commercial proxy services and leased virtual private servers. Officials said that mix let operators hide the Chinese origin of traffic by making it appear to come from devices outside the PRC, including machines near the targeted networks.
Attorney General Todd Blanche said state-sponsored hackers targeting U.S. critical infrastructure “will be stopped and prosecuted” and described the seizures as the latest in a series of technical operations against PRC-sponsored hacking. FBI Director Kash Patel said the tools were used “to hide the origin of their attacks” and tied the disruption to President Trump’s Cyber Strategy for America. Assistant Attorney General for National Security John A. Eisenberg said the seizures deny PRC-linked hackers tools used against critical infrastructure. The FBI San Diego Field Office, FBI Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Division’s National Security Cyber Section led the investigation. U.S. Attorney Adam Gordon and San Diego Special Agent in Charge Mark Remily issued supporting statements.
The same day, the FBI and National Security Agency published a cybersecurity advisory with indicators of compromise drawn from QTFY activity since at least 2018. Lumen Technologies’ Black Lotus Labs separately described the group’s infrastructure model. Officials noted prior court-authorized operations against other PRC-linked botnets, including Flax Typhoon in 2024 and Volt Typhoon in 2023, and a 2025 action that removed PlugX malware from more than 4,000 U.S. computers.
A spokesperson for the Chinese Embassy in Washington said the embassy was unfamiliar with the specifics of the Justice Department announcement, said China opposes cyberattacks, and accused the United States of using cybersecurity issues to smear China. Beijing has routinely denied responsibility for similar U.S. attributions. Nanjing Xinjiuwei did not issue a public response in U.S. coverage of the seizures.
The Justice Department did not publish a damage assessment for the named agencies. The FBI advisory urged organizations to review networks against the published indicators.
Support Independent Conservative News
RWTNews is independent conservative news — no corporate backing, no agenda driven by advertisers. We rely entirely on readers like you to keep the lights on and the truth coming. If you've found value in what you read here, consider supporting us with a one-time or monthly contribution. Every dollar goes directly toward keeping this site running and growing.
Secured by Stripe. Your payment info is never stored on our servers.
