US Reveals Large-Scale Chinese Cyber Campaign Against Government Structures
US authorities announced the dismantling of infrastructure belonging to a Chinese hacking group that, according to the American investigation, breached the networks of NASA, the Federal Reserve System, the Department of Justice, the Senate and other government agencies. The Justice Department and FBI seized domains of two platforms used to conduct and conceal cyberattacks.
The operation was carried out on August 26 based on court authorizations. The platforms in question are QScan and QTRouter, which, as US authorities claim, were created and maintained by the China-linked group QTFY.
According to declassified court documents, QTFY operates through the China-registered company Nanjing Xinjiuwei Network Technology. The American investigation alleges that it carried out hacking assignments, including for China's Ministry of State Security and the People's Liberation Army.
Among the victims of the cyberattacks, the US Department of Justice named NASA, the Federal Reserve System, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate.
In addition to American government structures, the investigation materials include hospitals, telecommunications companies, energy enterprises, financial organizations and defense contractors. According to the FBI, QTFY's infrastructure has been used to attack sensitive networks in the US and other countries since at least 2018.
How the hacking infrastructure worked
QScan was used to find vulnerable internet-connected devices and automatically infect them. In this way, thousands of Internet of Things devices worldwide fell under the attackers' control.
After infection, the devices were connected to the QTRouter system. It also included commercial proxy servers and rented virtual servers.
This infrastructure allowed the real source of attacks to be concealed. Malicious traffic could appear to come not from China, but from an infected computer or other device in a third country—sometimes even from the region where the attack target itself was located.
The US Department of Justice reported that the seized domains were directly built into QScan and QTRouter and were used for communication and authentication. After the domains came under US authorities' control, both platforms, according to the department, ceased to operate.
Chinese hackers linked to the military
Court materials state that among the QTFY members are former servicemen of the People's Liberation Army of China. According to the FBI, they used their previous connections to obtain contracts and subcontracts related to offensive cyber operations.
US authorities have not yet disclosed the full scale of penetration into government agency networks and have not reported which specific data may have been obtained as a result of the attacks.
The Chinese embassy in Washington did not respond to Reuters' request for comment on the new accusations. Beijing has repeatedly denied the involvement of Chinese authorities in the hacking operations attributed to them.
The current operation was another FBI intervention into the infrastructure of groups that Washington links to China. In 2025, the bureau removed the PlugX malware from more than 4,000 computers in the US, and earlier dismantled botnets that American authorities associated with the Flax Typhoon and Volt Typhoon groups.
Based on materials from: US Department of Justice, Reuters