Federal agents say they knocked offline Chinese-run tools that helped hackers reach NASA, the Federal Reserve, the Senate, and more.
Story Snapshot
- Justice Department seized domains tied to QScan and QTRouter, stopping their use.
- Officials link the platforms and group QTFY to years of U.S. agency targeting.
- FBI says the network hit critical infrastructure across 130+ countries.
- China denies the claims and calls past U.S. warnings “disinformation.”
What DOJ and FBI Say They Shut Down
The U.S. Department of Justice said it seized web domains for two platforms, called QScan and QTRouter, used in hacking campaigns tied to the Chinese government. The action, taken on August 26, followed court orders that rendered the platforms inoperable. Reporting on the case says the Federal Bureau of Investigation linked the activity to a state-backed group known as QTFY and said the targets included NASA, the Justice Department, the Federal Reserve, the U.S. Senate, and health agencies.
The Federal Bureau of Investigation described the effort as a disruption of a global botnet and proxy service used to hide attacker locations. Coverage citing the Federal Bureau of Investigation said the tools helped reach U.S. critical infrastructure and government networks. A San Diego field investigation reportedly tied the platforms to traffic routed through devices in more than 130 countries, showing the scale of the relay network rather than a single server farm.
How Officials Link the Tools to Beijing
Reporting on a Federal Bureau of Investigation affidavit says investigators tied the platforms to a Chinese contractor named Nanjing Xinjiuwei Network Technology Company. The affidavit reportedly stated that customers included China’s Ministry of State Security and the People’s Liberation Army, and that campaigns date back to at least 2018. While the affidavit underpins the seizures, the full technical exhibits were not public in the available reports, limiting outside review of every link.
A joint advisory from the National Security Agency, the Federal Bureau of Investigation, and U.S. Cyber Command warned that group QTFY used distributed platforms against military and critical infrastructure. Earlier guidance from the Cybersecurity and Infrastructure Security Agency said Chinese state actors often use layered encrypted proxies and small office or home routers to hide their tracks. Those advisories match the relay tactics described in the current case and help explain why officials focused on seizing the proxy layer.
What Is Known, What Is Not, and Why It Matters
Officials and reporters list major federal victims, but the public record does not confirm what data, if any, was taken from each name. The Federal Bureau of Investigation materials, as described by press, detailed categories of targets and methods, not a breach-by-breach impact report. That gap is common in national security cases, yet it fuels distrust across the political spectrum that leaders hide the ball when systems fail or when agencies cannot fully measure the damage.
Justice Department and the FBI Seize Platforms Operated and Used by China State-Sponsored Hacker group QTFY to Target U.S. Critical Infrastructure‼️
Among the victims of QTFY include:
✅National Aeronautics and Space Administration
✅Federal Reserve
✅Department of Energy… pic.twitter.com/3RAHXjWY7T— D (@D_Pheenyx) August 26, 2026
China continues to deny U.S. hacking claims. Chinese officials have called similar allegations “baseless,” a “political farce,” and part of a “collective disinformation campaign.” Those denials clash with repeated U.S. disruptions of botnets used to mask Chinese operations, such as the 2024 takedown that hit more than 200,000 devices and the campaign against the group known as Volt Typhoon. Readers should weigh the clear pattern of proxy abuse against the lack of full public forensics.
Why This Hits a Nerve for Americans
People on the right and left worry that powerful insiders let basic duties slide while they fight over headlines. Seeing federal targets like NASA, the Senate, and financial systems on a victim list deepens that concern. The case also shows how hackers ride on private home and small business gear to strike big targets, turning ordinary Americans into unwitting shields. That feels like one more sign that key systems are fragile and leaders are behind the curve.
What To Watch Next
Watch for unsealed court records with technical details, which could clarify exactly how QScan and QTRouter worked and who paid for them. Look for agency-by-agency notices confirming what was accessed and when. Track new guidance from the National Security Agency, the Federal Bureau of Investigation, and the Cybersecurity and Infrastructure Security Agency with indicators that defenders can use. Those steps would turn a headline seizure into lasting defense, not just a short-term win.
Sources:
feedpress.me, usatoday.com, wired.com, justice.gov, yahoo.com, bbc.com
© oldglorychronicle.com 2026. All rights reserved.













