Just Earth News | @justearthnews | 27 Aug 2026, 05:13 am Print
Cyber Attack US seizes China-linked hacking platforms used to target NASA, Senate and critical infrastructure. Representational image by Sora Shimazaki/Pexels
US law enforcement has seized internet domains that authorities say were used by China-linked hackers to target American government agencies and critical infrastructure, including NASA, the Federal Reserve and the US Senate.
The US Justice Department and FBI said on Wednesday that they had disrupted two interconnected hacking platforms, known as QScan and QTRouter, which were allegedly operated by a group called QTFY.
According to court documents unsealed in the Southern District of California, QTFY was employed by China-based Nanjing Xinjiuwei Network Technology Company and provided hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army.
The Justice Department said victims of QTFY's intrusion activity included NASA, the Federal Reserve, the US Senate, the departments of Energy and Justice, the Department of Health and Human Services and the National Institutes of Health.
US officials also said the operation targeted private-sector networks, including hospitals, universities, telecommunications providers, power companies, financial institutions and defence contractors.
QScan and QTRouter at the centre of operation
According to the Justice Department, QScan and QTRouter worked together to build and operate a large network of compromised devices.
QScan was used to scan internet-connected devices and automatically infect thousands of vulnerable systems around the world.
Those compromised devices were then incorporated into the QTRouter network, which was also made up of commercial proxy services and leased virtual private servers.
QTRouter effectively served as an obfuscation network, allowing hackers to conceal the Chinese origin of their activity.
Malicious communications could appear to originate from compromised computers outside China and, in some cases, from systems located close to the networks being targeted.
This arrangement made it harder for investigators to identify the true source of attacks and enabled QTFY and other users of the platform to disguise their operations.
Seized domains render platforms inoperable
The US authorities said the seized domains were embedded within both QScan and QTRouter and were necessary for functions including communication and authentication.
By taking control of those domains through court-authorised seizures, the Justice Department and FBI disrupted the platforms and rendered them inoperable, according to the department.
Attorney General Todd Blanche described the operation as part of a broader effort to dismantle Chinese state-sponsored hacking infrastructure.
"Federal law enforcement investigated and disabled the PRC's malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China," Blanche said.
"We are here to ensure security for the American people and will use every tool we have to keep that promise," he added.
FBI Director Kash Patel said the operation had disrupted a "global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure."
NASA, Federal Reserve, Senate among targets
The alleged campaign affected a broad range of US government and private-sector networks.
The Justice Department identified NASA, the Federal Reserve, the US Senate, the Department of Energy, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health among the organisations targeted by QTFY.
Court records indicate that the activity dates back years.
The FBI investigated an attempted attack against NASA in 2019, while other incidents involved government agencies and private-sector organisations.
The US Senate was also among the targets identified in the latest court documents, with the alleged activity extending into 2026.
The authorities have not publicly detailed the extent of information accessed or the damage caused in each incident.
Hackers targeted critical infrastructure
The alleged operation was not limited to government networks.
US authorities said QTFY also targeted hospitals, universities, telecommunications companies, electricity providers, financial institutions and defence contractors.
The scale of the operation reflects the use of compromised internet-connected devices as an intermediary layer. Instead of sending malicious traffic directly from China, the attackers could route activity through systems that had already been compromised elsewhere.
Cybersecurity authorities said the technique helped obscure the origin of the attacks and made the infrastructure more difficult to trace.
The National Security Agency, FBI and Cyber National Mission Force have issued a joint cybersecurity advisory containing indicators intended to help organisations identify potential QTFY activity.
China rejects US allegations
The Chinese government has rejected the US accusations.
A spokesperson for the Chinese embassy in Washington said China opposed and fought all forms of cyberattacks and urged Washington to stop using cybersecurity allegations to "smear or discredit China".
The US action comes amid continuing tensions between Washington and Beijing over cyber espionage and attacks on critical infrastructure.
US officials have previously carried out operations aimed at disrupting infrastructure associated with Chinese state-sponsored hacking groups.
The latest case adds QTFY, QScan and QTRouter to the growing list of China-linked cyber operations that US authorities say have targeted government systems and critical infrastructure.
FBI, NSA issue cybersecurity warning
Alongside the domain seizures, the FBI and NSA released technical information designed to help organisations detect activity associated with QTFY.
The advisory identifies the group's use of malicious distributed systems and compromised devices as part of its broader operational infrastructure.
The US authorities said dismantling the seized domains had disrupted the infrastructure used to coordinate the hacking campaign, while the cybersecurity advisory was intended to help potential victims identify and respond to related activity.
- US horror: 8 dead after gunman opens fire during family dinner in Montana
- Pakistan hospital fire horror: 13 children, mostly newborns, killed in massive blaze
- Mystery US Air Force C-17 Globemaster lands in Moscow as Ukraine peace talks remain deadlocked
- Trump administration plans largest mass visa revocation targeting up to 200,000 foreigners seeking asylum
- Pak Army officer storms student protest, 'beats' up students and fires shots; video goes viral

