US authorities dismantle China-linked hacking network

News Team
Written by News Team

The US Justice Department (DOJ) and Federal Bureau of Investigation (FBI) have disrupted a China-linked cyber operation involving two platforms, QScan and QTRouter, allegedly operated by the hacking group QTFY, which the China-based Nanjing Xinjiuwei Network Technology Company employs.

According to court documents, the infrastructure had been used since at least 2018 to target US government agencies, critical infrastructure, and private organisations.

Authorities allege that QScan identified and compromised vulnerable internet-connected devices, while QTRouter used those compromised systems to conceal the origin of cyberattacks.

FBI Director Kash Patel stated, “We announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.”

The investigation links the infrastructure to attacks targeting organisations including NASA, the Federal Reserve, the US Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

What FBI and DOJ found

On 26 August 2026, the DOJ and FBI revealed the details about this operation. The US government had obtained a court order allowing them to seize the domains associated with QScan and QTRouter. In the opinion of the government, the seized domains were not mere domain names of the administration of websites. Instead, these domains were incorporated into the malware and were necessary to perform certain tasks like communications and authentication.

Attorney General Todd Blanche said, “Federal law enforcement investigated and disabled the People’s Republic of China (PRC) malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

A cybersecurity advisory detailing QTFY’s operations and wider toolkit was simultaneously released by the FBI, NSA, and Cyber National Mission Force. According to the advice, since its founding in 2018, QTFY has created harmful distributed platforms, such as QScan for finding and exploiting vulnerabilities and QTRouter for hiding malicious activity. According to authorities, the group has targeted businesses in a variety of industries, including higher education, local government, telecommunications, and defence.

How two platforms worked together

According to court filings, Chinese cybersecurity firm QTFY allegedly provided hacking services to clients including China’s Ministry of State Security and the People’s Liberation Army. Authorities said the company operated two tools, QScan and QTRouter, which worked together to compromise thousands of internet-connected devices worldwide.

QScan reportedly infected vulnerable IoT devices and added them to the QTRouter network, which was then used to mask the origin of cyber intrusions by routing malicious traffic through compromised systems outside China.

Prosecutors said the seized domains were critical to the operation of both malware strains, handling functions such as communication and authentication. Their court-authorised seizure effectively disrupted the network, rendering QScan and QTRouter inoperable.

Multi-Year intrusions detailed

Court documents and US authorities revealed the China-linked hacking group QTFY has targeted a wide range of American government agencies, research institutions, and private-sector organisations over several years.

Some of the earliest attacks that have been highlighted by investigators go back to August 2019, where hackers were trying to penetrate NASA’s networks using a Pulse Secure virtual private network (VPN). Although the attack did not succeed, there was some evidence that the attackers had some ties to China.

Authorities said the group’s activities intensified in subsequent years. In September 2024, QTFY operators allegedly gained access to networks belonging to three US Department of Energy laboratories, the National Institutes of Health (NIH), and an unnamed agency within the Department of Health and Human Services (HHS). Investigators also linked the group to successful data theft operations targeting defence contractors, financial institutions, and universities earlier that year.

According to the FBI and National Security Agency (NSA), their research linked QTFY’s actions to at least 2018. The organisation is suspected of creating and disseminating malware, operating an obfuscation botnet, trading exploits via underground hacking networks, and carrying out cyber operations against vital systems throughout that time.

According to authorities, the group’s operations persisted until 2026. According to reports, QTFY analysed networks for vulnerabilities in March of that year and made an unsuccessful attempt to access systems connected to a US hospital and the US Senate. The instances, according to investigators, show a long-running effort that has developed to target a variety of government, healthcare, academic, and commercial organisations.

Years of cyber enforcement

The operation against QTFY is a component of a larger US initiative to interfere with cyber infrastructure that is purportedly connected to threat actors based in China. Technical disruption tactics, such as court-authorised domain seizures, malware deletions, and botnet takedowns, have become more and more important to US authorities in recent years.

According to the Department of Justice, the FBI eliminated PlugX malware from over 4,000 systems in the United States in 2025 as a result of attacks connected to the hacker group Mustang Panda, which has ties to China. A botnet made up of hundreds of thousands of infected internet-connected devices that investigators linked to Flax Typhoon was deactivated a year prior.

Additionally, in 2023, the FBI interfered with equipment that Volt Typhoon reportedly used to hide cyberattacks that targeted vital infrastructure both domestically and internationally.