
Two Chinese state-backed web platforms targeting vital US infrastructure and networks—such as NASA, the Federal Reserve and the US Senate—have been taken down by the FBI and the Department of Justice, officials announced on Wednesday.
Chinese Hacking Platforms Targeted Major US Agencies
According to legal records, the targeted platforms, QScan and QTRouter, were set up and maintained by Nanjing Xinjiuwei Network Technology Co, a Chinese firm linked to the cyber outfit known as 'QTFY'.
US Attorney General Todd Blanche stated that 'state-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted', adding that 'federal law enforcement investigated and disabled [China's] malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China [PRC].'
Today, the @FBI and @TheJusticeDept announced the disruption of a global botnet used by Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure.
— FBI Cyber Division (@FBICyberDiv) August 26, 2026
Our investigation attributes QTFY to the Nanjing Xinjiuwei Network Technology Company, which sells stolen… pic.twitter.com/I5xOueyg2U
Filings in the US District Court of the Southern District of California state that QTFY ran a fee-for-service cyber-hacking enterprise targeting entities on behalf of clients, including China's Ministry of State Security (MSS) and the People's Liberation Army.
Emphasising that Beijing actively opposes and combats every form of cyberattacks, the Chinese embassy spokesperson in Washington urged 'the US side to stop using cybersecurity issues to smear or discredit China'.
NASA, Senate and Critical Infrastructure Hit
Beyond these agencies, QTFY's hacking campaign compromised the Department of Energy, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health, as well as healthcare facilities, telecom providers, energy grids, financial institutions and defence contractors.
'We're taking the fight to PRC-sponsored cybercriminals to protect the critical services Americans rely on every day', said US Attorney Adam Gordon for the Southern District of California.
Analysts noted that prosecuting and stopping cyber-hacking operations remains difficult in practice because of the cross-border nature of threats, the relative anonymity of overseas actors and the speed at which sites can be set up or moved.
The China-linked hacking group QTFY provides tools for targeting critical systems in the U.S. and abroad. The FBI, NSA, and CNMF recommend organizations implement the recommended mitigations to counter their malicious tools: https://t.co/9xFqtP6CJT pic.twitter.com/WF6Fu9SY6K
— NSA Cyber (@NSACyber) August 26, 2026
Experts also raised concerns over major staff and funding cuts introduced by the Trump administration across key threat-monitoring agencies, such as the Federal Bureau of Investigation, National Security Agency (NSA), Federal Communications Commission and Cybersecurity and Infrastructure Security Agency (CISA).
How QTFY Infected Thousands of Devices
Details released by the Department of Justice on Wednesday show that QTFY's cyber tools worked together, with QScan detecting and automatically infecting thousands of smart gadgets worldwide—such as heart monitors, fitness bands and video doorbells—before incorporating them into the device network managed by QTRouter.
The department noted that QTRouter acted as an 'obfuscation network', giving QTFY and various 'malicious cyber actors' a way to mask their Chinese origins by ensuring digital signals appeared to originate from computers located beyond China's borders.
The @FBI, @NSAGov and @US_CYBERCOM have issued a Joint Cybersecurity Advisory to warn organizations about cyber threat activity by the China-linked hacking group QTFY.
— FBI Cyber Division (@FBICyberDiv) August 26, 2026
Since 2018, QTFY has developed malicious tooling, traded malware and exploits within freelance hacking… pic.twitter.com/vX7zlq5jol
An FBI affidavit revealed that QTFY's malicious cyber operations began as far back as 2018, noting that the outfit—also referred to as QT and QTCYBER—frequently recruited former PLA personnel who leveraged their networks to secure clients and land contracts.
US Seizes Platforms Used in Cyber Attacks
Legal filings validated the takedown of QScan and QTRouter, alleging that the US-based infrastructure was funded through money-laundering schemes and that the seized web domains served as hard-coded pillars for the malware's communication and authentication functions. In response, China continues to push back against state-sponsored hacking accusations, branding them 'unfounded' and 'a smear'.
Despite this, cybersecurity companies like Microsoft, Mandiant and CrowdStrike, alongside Western intelligence agencies, have named multiple Chinese state-supported threats. These include Volt Typhoon, said to be backed by the People's Liberation Army Cyberspace Force, and Salt Typhoon, reportedly sponsored by the MSS.




