- The Washington Times - Wednesday, August 26, 2026

Federal agents shut down two hacking platforms used by a China state-sponsored group to conceal cyberattacks on U.S. targets, including the Justice Department, NASA and the U.S. Senate.

Other victims of the computer intrusion include the Federal Reserve, the National Institutes of Health and the Energy and Health and Human Services departments, said the DOJ said Wednesday in announcing the enforcement action.

The Chinese-linked hackers also hit networks operated by hospitals, telecommunications providers, power companies, financial institutions and defense contractors. Those include a Michigan financial group, Ohio medical center, Missouri insurance agency and South Korean financial group, which the DOJ did not name.



The full impact of the hacks is currently unknown.

Attorney General Todd Blanche said the U.S. will not tolerate “state-sponsored malicious hackers preying on America’s critical infrastructure.”

“We are here to ensure security for the American people and will use every tool we have to keep that promise,” he said. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

The FBI and the DOJ shut down the QScan and QTRouter hacking platforms, which were created and operated by the People’s Republic of China-sponsored hacking group known as QTFY. The group was employed by China-based Nanjing Xinjiuwei Network Technology Company to target U.S. critical infrastructure and other sensitive networks, according to court documents.

The FBI described QTFY as operating a network of “hackers for hire.”

Advertisement
Advertisement

QTFY’s customers included the PRC’s Ministry of State Security and the People’s Liberation Army, according to court documents.

The Justice Department said there is probable cause to believe that the domains were used in a conspiracy to launder money.

QScan infects thousands of internet-of-things devices, which are then added to the QTRouter network that lets QTFY and other cyber actors conceal the PRC origin of their computer intrusion activities.

By routing internet traffic through the QScan-compromised devices, “Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets,” said the affidavit.

Since at least 2018, QTFY computer infrastructure has been used to compromise critical infrastructure and other sensitive networks in the U.S. and worldwide, according to the Justice Department’s affidavit.

Advertisement
Advertisement

Wednesday’s announcement is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC, including surveillance malware in thousands of U.S. computers and infected internet-of-things devices.

Alongside the domain seizures, the FBI and National Security Agency published a joint cybersecurity advisory Wednesday detailing indicators of compromise tied to QTFY, based on the agencies’ analysis of the group’s activity.

Lumen Technologies’ threat intelligence arm, Black Lotus Labs, also released its own report on QTFY’s tactics, techniques and procedures, giving network defenders a private-sector complement to the government’s findings.

Contact the author

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Please read our comment policy before commenting.