// DOSSIER — fbi-disruption-china-qtfy-hacking-infrastructure
FBI Disruption of China-Linked QTFY Hacking Infrastructure
REL_TIME: 29 Aug 2026 08:43Z · LANG: EN
The U.S. Department of Justice and the FBI executed a court-authorized operation to seize domains supporting QScan and QTRouter, two sophisticated hacking platforms operated by the Chinese state-sponsored group QTFY. Operating through the private contractor Nanjing Xinjiuwei Network Technology Company, the group targeted high-profile U.S. entities including NASA, the Federal Reserve, and the U.S. Senate. QScan served as a reconnaissance tool to identify and infect IoT devices, while QTRouter functioned as an obfuscation network to mask the Chinese origin of cyberattacks by routing traffic through compromised global infrastructure. The operation is part of a broader U.S. strategy to dismantle Chinese-backed botnets and proxy networks used for global espionage.
// Background
Nanjing Xinjiuwei Network Technology Company is a private Chinese firm that provides hacking services to China's civilian and military intelligence agencies. It operates as a 'digital quartermaster,' providing ready-made infrastructure for other state-linked hackers to find targets and hide their tracks. This case reflects a growing trend of Chinese intelligence relying on private contractors to conduct large-scale cyber espionage.
// Key Developments
- The FBI seized three hard-coded domains essential for the communication and authentication of the QScan and QTRouter platforms.
- QTFY is identified as a Chinese government contractor linked to the Ministry of State Security (MSS) and the People's Liberation Army (PLA).
- Targeted agencies include NASA, the Federal Reserve, the U.S. Senate, and the Departments of Energy, Justice, and Health and Human Services.
- QScan demonstrated massive scale, processing over 2 million scanning or exploitation tasks in a single day in 2024.
- The group exploited vulnerabilities in widely used products from Ivanti, Check Point, Fortinet, Citrix, and Microsoft.
- The disruption follows previous FBI actions against other Chinese hacking networks including Volt Typhoon, Flax Typhoon, and PlugX.
// Timeline
-
QTFY begins cyber operations and infrastructure development.
-
Attempted attack against NASA fails due to a previously patched security flaw.
-
Group exploits a Check Point security flaw, stealing data from over 300 U.S. organizations.
-
QTFY actors allegedly target a U.S. election system.
-
FBI and DOJ announce the seizure of domains and the disruption of QScan and QTRouter platforms.
// Perspectives
[U.S. Department of Justice / FBI]
Proactive and offensive; utilizing court-authorized technical operations to dismantle foreign state-sponsored infrastructure.
[Chinese Government]
Denial; officials consistently state they do not sponsor hacking operations against the United States.
[Cybersecurity Researchers (Lumen/Frenos)]
Analytical but cautious; viewing the takedown as a significant disruption that imposes costs on the adversary while acknowledging that state-sponsored groups will likely rebuild.
[American Hospital Association]
Concerned; emphasizing the vulnerability of IoT devices in medical settings and the risk to critical healthcare infrastructure.
// Quotes
“These tools were used by PRC cyber actors to hide the origin of their attacks.”
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.”
“The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations.”
“The line between foreign criminal hacking groups, their infrastructure and hostile intelligence services is becoming increasingly blurred.”