The U.S. Department of Justice said it disrupted a long-running Chinese state-sponsored hacking campaign by seizing domains associated with two malicious platforms, QScan and QTRouter. The operation, conducted with the FBI, rendered the botnet inoperable by removing the infrastructure used for command, control, and authentication.
The platforms were operated by a group identified in court documents as QTFY, which was employed by Nanjing Xinjiuwei Network Technology Company, a China-based firm.
DOJ filings allege QTFY’s clients included China’s Ministry of State Security and the People’s Liberation Army. QScan was used to infect thousands of internet-connected devices globally, which were then added to the QTRouter network to obfuscate the origin of attacks, making them appear to come from outside China.
The campaign, active since 2018, targeted U.S. critical infrastructure and sensitive networks.
Confirmed victims and targets include Department of Justice, NASA, Federal Reserve, Department of Energy, Department of Health and Human Services, and the National Institutes of Health. Others include the U.S. Senate, hospitals, telecommunications providers, power companies, financial institutions, defense contractors, and four unnamed companies in the U.S. and South Korea.
Notable specific incidents include a failed attempt to breach NASA networks via a VPN vulnerability in August 2019 and successful intrusions at three unnamed Department of Energy laboratories, the NIH, and an HHS agency in September 2024.
FBI Director Kash Patel said the tools were used by Chinese government actors to hide the origin of their attacks. Attorney General Todd Blanche described the seizure as the latest in a series of operations to dismantle PRC-sponsored hacking.
The Chinese Embassy in Washington said in a statement that the "Chinese government firmly opposes and combats all forms of cyberattacks," while Beijing routinely denies responsibility for such activities. This incident follows other recent Chinese-linked compromises, including breaches of U.S. House committee networks and major telecommunications companies.