China-Linked Hackers Targeted NASA, Federal Reserve and US Senate; FBI Seizes Hacking Platforms

China-Linked Hackers Targeted NASA, Federal Reserve and US Senate; FBI Seizes Hacking Platforms

 

Washington: The United States has disrupted a China-linked cyber operation that allegedly targeted some of the country’s most sensitive government networks, including NASA, the Federal Reserve, the US Senate, the Justice Department and the Department of Energy.

The US Justice Department and FBI said on August 26 that they had seized internet domains linked to two interconnected hacking platforms, QScan and QTRouter, which investigators say were operated by a China-based group known as QTFY. Court documents unsealed in the Southern District of California allege that QTFY operated through Nanjing Xinjiuwei Network Technology Company and provided hacking capabilities to customers including China’s Ministry of State Security and the People’s Liberation Army.

The case highlights the scale of a cyber campaign that US investigators say has been active since at least 2018, targeting government agencies as well as hospitals, universities, telecommunications companies, power providers, financial institutions and defence contractors.

NASA, Federal Reserve and Senate among targets

According to the FBI affidavit, QTFY activity involved networks belonging to NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate.

However, US authorities have stressed that not every attempted intrusion was successful. Investigators said, for example, that hackers unsuccessfully attempted to exploit a vulnerability in a NASA VPN in 2019. The Senate was also among networks targeted in 2026.

The affidavit further says that hackers carried out intrusions at three unnamed Energy Department laboratories, an HHS agency and the NIH in 2024. The campaign also involved successful data theft from unnamed defence contractors, financial institutions and universities, according to a joint US cybersecurity advisory.

QScan and QTRouter: How the operation worked

At the centre of the operation were QScan and QTRouter.

QScan was allegedly used to scan internet-connected devices for vulnerabilities and automatically compromise susceptible systems. Thousands of infected IoT devices could then be incorporated into the QTRouter network.

QTRouter, in turn, acted as an obfuscation layer. It combined compromised devices with commercial proxy services and leased virtual private servers to disguise the actual origin of malicious traffic.

That meant cyberattacks originating from China could appear to come from compromised computers or other devices located elsewhere — potentially even near the network being targeted. US investigators say the technique made attribution considerably more difficult.

FBI seizes domains, disrupts hacking infrastructure

The FBI and Justice Department obtained court authorisation to seize domains that were hard-coded into QScan and QTRouter and used for essential functions such as communication and authentication.

By taking control of those domains, US authorities said they effectively rendered both platforms inoperable, disrupting the infrastructure used to coordinate the alleged hacking campaign.

The action is part of a broader US effort to dismantle infrastructure used by China-linked cyber groups. The FBI has previously carried out operations against botnets and malware associated with groups such as Volt Typhoon, Flax Typhoon and Mustang Panda.

Critical infrastructure also in the crosshairs

The alleged campaign extended well beyond Washington’s government networks.

US authorities said QTFY-linked activity targeted hospitals, telecommunications providers, power companies, financial institutions and defence contractors. The use of compromised internet-connected devices as intermediary nodes allowed attackers to blend malicious traffic into legitimate internet activity and obscure their location.

Cybersecurity researchers have described the infrastructure as a kind of cyber “quartermaster” operation, providing tools for reconnaissance, compromised-device management and traffic routing to support broader espionage activities.

US releases technical warning

Alongside the domain seizures, the FBI and National Security Agency released technical information and indicators of compromise to help organisations identify possible QTFY-related activity.

The advisory draws on investigations into the group’s operations dating back to at least 2018 and is intended to help network defenders detect the tactics and infrastructure associated with the campaign.

China rejects US allegations

China has rejected US accusations of state-backed hacking and has previously denied sponsoring cyberattacks against American targets.

The latest US action comes amid continuing tensions between Washington and Beijing over cyber espionage, critical infrastructure security and allegations of state-sponsored hacking.

The QTFY case nevertheless provides a fresh illustration of how cyber operations can use private companies, compromised devices and proxy networks to create layers between attackers and their ultimate targets.

For US authorities, the seizure represents more than the shutdown of two hacking platforms: it is an attempt to disrupt an infrastructure model that investigators say enabled China-linked cyber actors to operate across borders while concealing the true source of their attacks.

Leave a Reply

Your email address will not be published. Required fields are marked *