Skip to main content
SQD
Intelligence Terminal // CORE_NODE_01
// AD SLOT — top

// DOSSIER — fbi-disruption-china-qtfy-hacking-infrastructure

AMERICAS ASIA-PACIFIC UNITED STATES CHINA CYBER

FBI Disruption of China-Linked QTFY Hacking Infrastructure

REL_TIME: 29 Aug 2026 08:43Z · LANG: EN

// Disseminate
FBI Disruption of China-Linked QTFY Hacking Infrastructure
David Wright · CC BY-SA 2.0 · source
// AD SLOT — mid

The U.S. Department of Justice and the FBI executed a court-authorized operation to seize domains supporting QScan and QTRouter, two sophisticated hacking platforms operated by the Chinese state-sponsored group QTFY. Operating through the private contractor Nanjing Xinjiuwei Network Technology Company, the group targeted high-profile U.S. entities including NASA, the Federal Reserve, and the U.S. Senate. QScan served as a reconnaissance tool to identify and infect IoT devices, while QTRouter functioned as an obfuscation network to mask the Chinese origin of cyberattacks by routing traffic through compromised global infrastructure. The operation is part of a broader U.S. strategy to dismantle Chinese-backed botnets and proxy networks used for global espionage.

// Background

Nanjing Xinjiuwei Network Technology Company is a private Chinese firm that provides hacking services to China's civilian and military intelligence agencies. It operates as a 'digital quartermaster,' providing ready-made infrastructure for other state-linked hackers to find targets and hide their tracks. This case reflects a growing trend of Chinese intelligence relying on private contractors to conduct large-scale cyber espionage.

// Key Developments

  • The FBI seized three hard-coded domains essential for the communication and authentication of the QScan and QTRouter platforms.
  • QTFY is identified as a Chinese government contractor linked to the Ministry of State Security (MSS) and the People's Liberation Army (PLA).
  • Targeted agencies include NASA, the Federal Reserve, the U.S. Senate, and the Departments of Energy, Justice, and Health and Human Services.
  • QScan demonstrated massive scale, processing over 2 million scanning or exploitation tasks in a single day in 2024.
  • The group exploited vulnerabilities in widely used products from Ivanti, Check Point, Fortinet, Citrix, and Microsoft.
  • The disruption follows previous FBI actions against other Chinese hacking networks including Volt Typhoon, Flax Typhoon, and PlugX.

// Timeline

  1. QTFY begins cyber operations and infrastructure development.

  2. Attempted attack against NASA fails due to a previously patched security flaw.

  3. Group exploits a Check Point security flaw, stealing data from over 300 U.S. organizations.

  4. QTFY actors allegedly target a U.S. election system.

  5. FBI and DOJ announce the seizure of domains and the disruption of QScan and QTRouter platforms.

// Perspectives

[U.S. Department of Justice / FBI]

Proactive and offensive; utilizing court-authorized technical operations to dismantle foreign state-sponsored infrastructure.

[Chinese Government]

Denial; officials consistently state they do not sponsor hacking operations against the United States.

[Cybersecurity Researchers (Lumen/Frenos)]

Analytical but cautious; viewing the takedown as a significant disruption that imposes costs on the adversary while acknowledging that state-sponsored groups will likely rebuild.

[American Hospital Association]

Concerned; emphasizing the vulnerability of IoT devices in medical settings and the risk to critical healthcare infrastructure.

// Quotes

“These tools were used by PRC cyber actors to hide the origin of their attacks.”

[Kash Patel] — FBI Director commenting on the disruption of the global botnet and hacking platform.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.”

[Todd Blanche] — U.S. Attorney General's statement following the court-authorized domain seizures.

“The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations.”

[Lumen Technologies (Black Lotus Labs)] — Analysis of QTFY's role as a provider of shared multi-tenant utility networks for state-sponsored actors.

“The line between foreign criminal hacking groups, their infrastructure and hostile intelligence services is becoming increasingly blurred.”

[John Riggi] — American Hospital Association national advisor for cybersecurity discussing the threat to healthcare systems.
// AD SLOT — bottom

// Related Briefs