Full Breakdown
Chinese State-Sponsored Hackers Disrupted After Targeting U.S. Agencies
8/28/2026, 2:38:17 AM
Core Seizure of Hacking Infrastructure
On Wednesday, the U.S. Department of Justice and the FBI announced the court-ordered seizure of three domains that powered the QScan and QTRouter platforms. The seizures rendered the malware inoperable. Court documents identify the operator as the Chinese state-sponsored group “QTFY,” employed by Nanjing Xinjiuwei Network Technology Company. QTFY’s paying customers included China’s Ministry of State Security and the People’s Liberation Army. The DOJ listed the Federal Reserve, the U.S. Senate, NASA, the Departments of Energy, Justice, Health and Human Services, the National Institutes of Health, and other critical-infrastructure entities as victims.
Background on QTFY and Its Operations
QTFY has been active since at least 2018, using a two-stage architecture. QScan scanned the global internet for vulnerable IoT devices—home routers, security cameras, and other “smart” endpoints—and infected thousands of them. Infected devices were fed into QTRouter, which combined the compromised hardware with commercial proxy services and leased servers to create an obfuscation network that masked the origin of attacks.
Scope of Intrusions
- Scanning volume: On a single day in 2024, QScan handled more than two million scanning and exploit tasks and housed over 200 proof-of-concept exploits.
- Geographic reach: Devices in more than 130 countries were drawn into the network.
- Targets: The FBI affidavit cites data theft from over 300 organizations, including U.S. defense contractors, financial institutions, universities, hospitals, power companies, telecommunications providers, and election-infrastructure systems.
Official Statements & Responses
Attorney General Todd Blanche said the operation demonstrates the government’s commitment to protecting America’s critical infrastructure and that “state-sponsored malicious hackers … will be stopped and prosecuted.” FBI Director Kash Patel framed the takedown as part of a broader push against Chinese-linked cyber operations, noting that the seized domains were essential to the malware’s functionality.
Conflicting Reports & Gaps
- The DOJ did not disclose the extent of damage or the specific data exfiltrated from the affected agencies.
- An FBI advisory listed the victim agencies but provided no details on what information was accessed or whether operations were disrupted.
Verbatim Quotes
- “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” — Attorney General Todd Blanche
- “QTFY is another example of how China’s cyber ecosystem has blurred the line between commercial cybersecurity and state-sponsored operations,” — Aaron Shraberg, senior intelligence team lead at Flashpoint
- “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” — FBI Director Kash Patel
What’s Next
The accusations surface ahead of Chinese President Xi Jinping’s scheduled visit to the United States on September 24, a summit that U.S. officials have indicated may include discussion of the recent hacking disclosures.
