Tuesday, September 1, 2026
WECUNews
Politics

FBI, DOJ Dismantle Chinese Hacking Platforms After 8-Year Run

An eight-year Chinese state-sponsored hacking operation targeting NASA, the Federal Reserve and the U.S. Senate has been dismantled — and the same group scanned a U.S. election system as recently as June.

By Lynn Matthews - August 28, 2026
FBI, DOJ Dismantle Chinese Hacking Platforms After 8-Year Run

The Justice Department and FBI said Wednesday they had seized internet domains used by two Chinese state-linked hacking platforms that targeted U.S. government and critical networks for about eight years, including NASA, the Federal Reserve, Energy Department laboratories and federal health agencies.

Prosecutors said a court order in the Southern District of California disabled tools known as QScan and QTRouter by seizing three domains hard-coded into the malware for communication and authentication — qtproxy.xyz, qt-proxy.org and qt-team.com — rendering both platforms inoperable. Officials described the action as a technical disruption of command-and-control infrastructure, not an indictment of named operators.

An affidavit unsealed in San Diego attributed the platforms to a group identified as QTFY, employed by Nanjing Xinjiuwei Network Technology Co. The filing said the company sold hacking services to paying customers that included China’s Ministry of State Security and the People’s Liberation Army. Court papers also said QTFY members include former PLA personnel who used those relationships to obtain offensive-cyber contracts.

FBI Director Kash Patel said the tools were used “to hide the origin of their attacks.” Attorney General Todd Blanche said “state-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” No individual charges were announced with Wednesday’s seizure.

Eight years of intrusion attempts

Court papers said the infrastructure had been used to compromise critical networks in the United States and elsewhere since at least May 2018, with operators routing traffic through compromised internet-connected devices, commercial proxies and leased servers so the attacks would not appear to originate in China. QScan scanned for and infected IoT devices; QTRouter then used those devices as an obfuscation network.

The Justice Department listed NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate among “victims of QTFY computer intrusion activity.” That official list mixes successful breaches with targeting that did not always succeed. Public filings do not detail what data, if any, was taken from each named agency.

Not every attempt succeeded. An August 2019 attempt to exploit a NASA virtual private network vulnerability failed. Politico, citing the affidavit, also described a limited-scope 2019 incident involving the Federal Reserve.

In September 2024, the group carried out intrusions at three unnamed Energy Department laboratories, an NIH facility, an HHS agency — identified in some reporting as the Health Resources and Services Administration — and an unnamed U.S. security device manufacturer. That wave has been tied to zero-day vulnerabilities in Ivanti Cloud Services Appliance software. Separate 2024 activity using a Check Point Quantum Gateway flaw was described as yielding server configuration files and account details from more than 300 organizations, including defense contractors, financial institutions and universities.

A scan of election infrastructure

In June 2026, the same group scanned a U.S. election system, according to the affidavit and a related advisory; officials said the scan did not succeed. Material released with the case also described an earlier, unsuccessful attempt against election-related networks in 2019. A March 2026 scan of Senate and hospital networks likewise failed to gain access, according to a joint advisory from the FBI, NSA and U.S. Cyber Command’s Cyber National Mission Force.

Officials said the broader campaign also targeted hospitals, telecommunications providers, power companies, financial institutions and defense contractors in the United States and South Korea.

China's response

The Chinese Embassy in Washington said Beijing “firmly opposes and combats all forms of cyberattacks in accordance with the law” and urged the United States “to stop using cybersecurity issues to smear or discredit China.” China’s Foreign Ministry later called the U.S. statement lacking in evidence and accused Washington of smearing Beijing under the pretext of cybersecurity. China routinely denies U.S. accusations of state-sponsored hacking.

What this takedown does and doesn't mean

Wednesday’s announcement describes a technical disruption of the group’s command-and-control infrastructure, not a public accounting of what data was stolen from each victim and not a prosecution of the operators. Cybersecurity officials note that similar hacking toolsets are often rebuilt after a domain seizure, meaning this disruption is unlikely to be the last word on QTFY’s activity.

The FBI and NSA also published a cybersecurity advisory with indicators of compromise dating to at least 2018. DOJ pointed to related private-sector analysis from Lumen’s Black Lotus Labs.

Sources:

Justice Department press release, Aug. 26, 2026: https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers

Reuters, Aug. 26, 2026: https://www.reuters.com/world/china/china-sponsored-hacking-platforms-seized-by-us-justice-department-says-2026-08-26/

Politico, Aug. 26, 2026: https://www.politico.com/news/2026/08/26/doj-fbi-china-hacks-01050956

The Register, Aug. 27, 2026: https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742

TechTimes affidavit timeline: https://www.techtimes.com/articles/325708/20260827/china-hacked-nasa-federal-reserve-fbi-seizes-platforms-behind-eight-year-breach.htm

ABC News: https://abcnews.com/Politics/fbi-chinese-hacking-group-targeted-government-agencies-hospitals/story?id=135977942

New York Post: https://nypost.com/2026/08/26/us-news/chinese-hackers-infiltrated-nasa-doj-and-other-us-government-computer-systems-affidavit/

Chinese Foreign Ministry briefing, Aug. 27, 2026: https://www.fmprc.gov.cn/eng/xw/fyrbt/202608/t20260827_12011637.html

FBI/NSA advisory (PDF): https://www.ic3.gov/CSA/2026/260826.pdf

Have a correction or tip? See our corrections policy or contact the newsroom.

Comments

to join the discussion.

Loading comments...

FBI, DOJ Dismantle Chinese Hacking Platforms After 8-Year Run - WECU News