WASHINGTON, D.C. — The hacking platforms QScan and QTRouter were used by a Chinese state-sponsored hacking group identified as QTFY. The QTFY hacking group is allegedly operated by Nanjing Xinjiuwei Network Technology Company, a contractor based in Nanjing, China. The QTFY group's customers allegedly included China's Ministry of State Security and the People's Liberation Army.
FBI Director Kash Patel stated that the FBI seized adversary infrastructure and shut down the platforms. Lumen Technologies null-routed certain domains to render them inoperable. Federal agencies plan to release an advisory on the hackers' techniques.
The QScan tool was designed to scan for vulnerabilities in internet-of-things devices to add them to botnets. The QTRouter service managed customer access to the botnet network and commercial proxy services. Nanjing Xinjiuwei Network Technology Company was established in 2018 and had 17 employees as of 2025. Employees of Nanjing Xinjiuwei Network Technology Company include former members of the People's Liberation Army.
The hackers breached networks at NASA, the National Institutes of Health, the Department of Justice, the Department of Health and Human Services, three Department of Energy National Laboratories, the Federal Reserve, and the US Senate. Targeted industries included power companies, telecommunications providers, hospitals, financial institutions, and defense contractors. Specific targets cited in the affidavit included a medical center in Ohio, financial groups in Michigan and South Korea, and an insurance agency in Missouri.
Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, provided analysis on the operation. "The scale of the operation is giant," Rouse said. He stated that the company and people involved have very close ties to the highest levels of the People's Liberation Army. He noted that it was difficult to see state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were co-opting.
"The hacking operations appeared to be focused on traditional espionage and information collection," Rouse said. He stated that the disruption would have a direct effect on the company and its perception in China. He added that he assumes the hackers will stand up new infrastructure.
Why It Matters
The disruption addresses a campaign targeting critical US infrastructure, including government agencies and private sector entities. The scope of the breach involved multiple federal departments and key industries such as energy, healthcare, and finance. The involvement of a contractor with alleged ties to Chinese state security organs shows the use of third-party entities in cyber operations.
Dakota Cary, a China analyst at SentinelOne, stated that the number of companies offering niche offensive services has exploded over the last decade. This context suggests that disrupting one node may not eliminate the broader capability, as indicated by assessments that hackers may establish new infrastructure.
Timeline
The hacking campaigns using these proxy networks date back to at least 2018. Hackers unsuccessfully attempted to access NASA networks in August 2019. Hackers successfully breached networks at the National Institutes of Health, the Department of Health and Human Services, and a US security-device manufacturer in September 2024.
On July 8, 2025, the United States Department of Justice announced the arrest of Xu Zewei, a Chinese state-sponsored contract hacker, who was charged with involvement in the HAFNIUM computer intrusion campaign between February 2020 and June 2021. Xu was arrested in Italy and faced extradition proceedings.
What's New
Authorities seized three internet domains associated with the hacking platforms QScan and QTRouter. Attorney General Todd Blanche declined to specify what President Trump would discuss with Chinese leadership regarding the hacking activity.
Attorney General Todd Blanche stated that the US has talked about this activity with counterparts in China for many years and that it has to stop.
forum Comments (0)
No comments yet. Be the first to comment.