- Chinese hackers broke into NASA and the Senate in a big security breach, prompting federal law enforcement to investigate and disable the PRC's malicious software.
- Seizing the domains rendered the malware platforms inoperable, disrupting a global botnet, and the FBI and NSA issued a cybersecurity advisory with detection indicators.
- QScan automatically infected thousands of internet-connected devices, which were then incorporated into QTRouter, a network controlled by the hacking group, using commercial proxy services and leased virtual private servers.
- The platform concealed the Chinese origin of activities by making malicious communications appear to originate from compromised computers outside China, sometimes near the targeted network.
U.S. law enforcement has taken significant action against Chinese state-sponsored hackers, disrupting their operations that targeted critical American infrastructure, including NASA and the U.S. Senate. The Justice Department and FBI reported the seizure of hacking platforms known as QScan and QTRouter, utilized by the hacking group QTFY.13
Court documents revealed that QTFY provided hacking services to clients such as the Chinese Ministry of State Security and the People's Liberation Army. The group was linked to the Nanjing Xinjiuwei Network Technology Company, a technology firm based in China. The hackers targeted not only government entities but also private sector infrastructure, including hospitals, universities, and financial institutions.
According to the Justice Department, the hackers used the seized platforms to infiltrate various agencies, including the Federal Reserve and the National Institutes of Health. The operation led to the disabling of malicious software that had infected thousands of devices globally, effectively dismantling a global botnet.2
Attorney General Todd Blanche emphasized the commitment to ensuring security for the American people, stating, "We are here to ensure security for the American people and will use every tool we have to keep that promise." The FBI and National Security Agency also issued a cybersecurity advisory to help organizations detect potential QTFY activity.
“Attorney General Todd Blanche said federal law enforcement investigated and disabled the PRC's malicious software, the latest in a series of technical operations. FBI Director Kash Patel said the operation disrupted a "global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure."”









