US Justice Department Dismantles Chinese State-Backed Hacking Network Behind Breaches of NASA, the Federal Reserve and the Senate

The U.S. Department of Justice and the FBI have seized the digital infrastructure behind two Chinese-built hacking tools, "QScan" and "QTRouter," used to break into NASA, the Federal Reserve, the Justice Department itself, and the U.S. Senate. Officials say a Nanjing-based tech company built the tools for China's military and intelligence services, part of a growing industry of private hackers-for-hire working on Beijing's behalf.

Aug 27, 2026 - 00:14
0
US Justice Department Dismantles Chinese State-Backed Hacking Network Behind Breaches of NASA, the Federal Reserve and the Senate

.

A Sweeping Takedown of Chinese Cyber Infrastructure

U.S. authorities announced on Wednesday that they had seized internet domains tied to a Chinese hacking operation that infiltrated some of the country's most sensitive institutions. The Justice Department said the seizures targeted two interlinked tools known as QScan and QTRouter, which together formed the backbone of a years-long espionage campaign.

According to the department, the affected organizations included NASA, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. Even the Justice Department itself was among the victims.

.

How the Hacking Tools Worked

Officials described QScan as a scanning tool that automatically searched for and infected vulnerable internet-connected devices around the world — everything from routers to other "smart" (internet-connected) hardware. Once compromised, these devices were folded into QTRouter, a network built to disguise the true origin of the attacks.

By routing malicious traffic through hijacked devices sitting outside China — sometimes even inside the very networks being targeted — the attackers made their activity look like ordinary local internet traffic. This is a common tactic in state-sponsored hacking (cyberattacks carried out or funded by a government), designed to delay detection and complicate attribution.

Because the seized web domains were built directly into the malicious software, disabling them rendered both tools inoperable, according to the Justice Department.

.

Who Was Behind It

Court documents unsealed in California identify the group responsible as "QTFY," a team working for a company called Nanjing Xinjiuwei Network Technology Company, based in the eastern Chinese city of Nanjing. U.S. officials say the company's clients included China's Ministry of State Security, the country's main civilian intelligence agency, as well as the People's Liberation Army, China's military.

Public business records show the firm was founded in 2018 and employed around 17 people as of last year — a modest workforce for a company allegedly tied to state-level espionage operations. Investigators say the group's infrastructure had been used to compromise critical infrastructure and other sensitive networks worldwide since at least 2018.

The Chinese Embassy in Washington did not immediately respond to requests for comment. Beijing has consistently denied involvement in hacking operations, a position it has repeated in past cases of alleged state-sponsored cyber activity.

.

A Booming Industry of Hackers-for-Hire

Cybersecurity researchers say this case fits a well-documented pattern: rather than relying solely on in-house government hackers, Chinese state agencies increasingly contract private companies to carry out intrusions on their behalf. This arrangement offers Beijing a degree of deniability while letting contractors build specialized tools and expertise.

Dakota Cary, a China-focused analyst at cybersecurity firm SentinelOne, said the number of companies offering these specialized offensive services has grown sharply over the past decade. He noted that this fragmentation makes it more difficult for Western defenders to track and link hacking campaigns to a single source.

Cary added that while actions like Wednesday's takedown disrupt individual operations, the broader marketplace of Chinese contractors supplying these services makes a full return to activity likely.

.

A Pattern That Predates This Case

This is not the first time U.S. authorities have dismantled Chinese-linked hacking infrastructure. In 2023, the FBI disrupted a botnet (a network of hijacked devices controlled remotely) tied to a separate Chinese state-sponsored group known as Volt Typhoon, which had also targeted American critical infrastructure.

Security researchers have separately documented a wider ecosystem of Chinese contractors offering hacking services to state agencies, including firms exposed in past leaks that revealed low-paid staff carrying out espionage on behalf of government clients. Taken together, these cases point to a deliberate strategy: outsourcing intrusions to give Chinese authorities a layer of separation from the hacking itself while expanding their reach.

.

What Comes Next

Alongside the domain seizures, the FBI and the National Security Agency issued a joint cybersecurity advisory listing technical indicators that organizations can use to detect whether they were compromised by QScan or QTRouter. This is intended to help potential victims — including private companies whose devices may have been unknowingly conscripted into the network — identify and remove the infection.

For now, U.S. officials are framing the takedown as a significant disruption rather than a final resolution. Given how quickly China's hacking-for-hire industry has grown, experts caution that similar operations are likely to resurface under new tools and new front companies in the future.


.

Sources:

  1. U.S. Department of Justice, Office of Public Affairs — https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
  2. U.S. Department of Justice — Affidavit (court filing) — https://www.justice.gov/opa/media/1459096/dl?inline
  3. CNN Politics — https://www.cnn.com/2026/08/26/politics/us-alleged-chinese-cyber-spying-campaign

.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User