Full Breakdown
U.S. Justice Department Disrupts China-Backed Hacking Operation Targeting Federal Agencies
8/27/2026, 8:41:18 AM
Core Event: Seizure of QScan and QTRouter Domains
On August 26, the U.S. Department of Justice (DOJ) and the FBI announced the court-ordered seizure of the internet domains that powered the hacking platforms “QScan” and “QTRouter.” Unsealed filings in the Southern District of California show the platforms were created and run by the Chinese state-sponsored group QTFY, employed by Nanjing Xinjiuwei Network Technology Company. The DOJ said the tools were used to infiltrate a range of U.S. critical-infrastructure and sensitive networks.
Background & Context
QTFY provides “hacker-for-hire” services to the Ministry of State Security and the People’s Liberation Army. Its infrastructure has supported cyber-espionage campaigns since at least 2018, targeting government and private sectors worldwide. Prior incidents cited in the affidavit include an attempted NASA breach in 2019, a 2020 intrusion of an Ohio medical center, and 2024 attacks on Department of Energy laboratories and the National Institutes of Health.
Timeline
- 2018 – QTFY’s botnet begins compromising U.S. networks.
- 2019 – Unsuccessful attempt to access NASA systems.
- 2020 – Breach of an Ohio medical center.
- 2024 – Intrusions of DOE laboratories and NIH.
- 2026 – Senate systems breached; DOJ and FBI seize QScan and QTRouter domains, rendering the platforms inoperable.
Data & Statistics
- The platforms scanned and infected thousands of IoT devices worldwide, incorporating them into the QTRouter “obfuscation network.”
- Victims listed in the affidavit include the Department of Justice, NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, plus hospitals, telecom providers, power companies, financial institutions, defense contractors, and four unnamed firms in the United States and South Korea.
- The seized domains were hard-coded into both QScan and QTRouter malware, disabling the tools after the takedown.
Official Statements & Responses
Attorney General Todd Blanche emphasized aggressive prosecution: “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.” He credited the FBI’s San Diego field office, the Cyber Division, and DOJ partners for the success. The DOJ did not disclose the extent of data exfiltrated or system damage. The Chinese Embassy declined to comment.
Conflicting Reports & Gaps
- The filing lists compromised agencies but provides no detail on whether confidential data was accessed or altered.
- No public attribution of specific stolen information has been confirmed, leaving the true impact uncertain.
Verbatim Quotes
- “State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.” — Attorney General Todd Blanche
- “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” — FBI Director Kash Patel
These statements capture the U.S. government’s characterization of the threat and the technical nature of the seized tools.
