FBI Disrupts China-Linked Hacking Network Behind Attacks on NASA, DOJ, and U.S. Senate
U.S. authorities dismantle digital infrastructure tied to Chinese state-affiliated cyber tools targeting federal agencies.
FBI and DOJ Operation
The Department of Justice and Federal Bureau of Investigation executed a coordinated operation to seize digital infrastructure linked to two malicious tools, QScan and QTRouter, developed by a Chinese state-affiliated entity known as QTFY. Judicial records establish ties to a firm in Nanjing, with QTFY providing cyber intrusion services to clients including the Chinese Ministry of State Security and the People’s Liberation Army.
Compromised Systems
The targeted systems included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
Malware Analysis: QScan and QTRouter
QScan functioned as a scanning mechanism to identify and compromise internet-connected devices globally, integrating them into a network controlled by QTFY. QTRouter then utilized these infiltrated devices alongside commercial proxy services and rented cloud servers to construct an obfuscation network, enabling QTFY to reroute cyberattacks through external machines and mask the true origin of traffic.
Seizure of Domains
The seizure of domains embedded in both malware variants disrupted their core functionalities, including communication and authentication processes, as outlined in court documents.
FBI Director’s Statement
FBI Director Kash Patel emphasized this action as part of an ongoing initiative to counter cyber activities attributed to Chinese state actors. The tools were instrumental in concealing the geographic source of attacks, according to the agency.
“This marks the latest in a sequence of operations targeting Chinese cyber threats,” said FBI Director Kash Patel.
Previous Cybersecurity Efforts
In 2025, the FBI removed PlugX malware from over 4,000 U.S. systems compromised by the Mustang Panda group. A year prior, it neutralized a botnet comprising hundreds of thousands of infected IoT devices leased to Chinese government clients by Flax Typhoon. In 2023, the FBI dismantled an alternative botnet used by Volt Typhoon to conceal intrusions into U.S. and international infrastructure.
Ongoing Threats and Collaborations
The FBI and National Security Agency issued a joint advisory detailing technical indicators associated with QTFY’s activities. Researchers at Lumen Technologies’ Black Lotus Labs published an analysis of the group’s methodologies. The agencies confirmed ongoing efforts to counter cyber operations linked to the People’s Republic of China.
