Cyber Security News

FBI Shuts Down China-Linked Hacking Platforms Used to Target NASA and U.S. Networks

The U.S. Department of Justice and FBI have seized domains associated with two China-linked hacking platforms, QScan and QTRouter, allegedly used to target NASA, federal agencies, critical infrastructure, and sensitive U.S. networks.

Court documents unsealed in the Southern District of California link the infrastructure to a People’s Republic of China state-sponsored group tracked as QTFY. The group is accused of operating out of Nanjing Xinjiuwei Network Technology Company.

This China-based firm allegedly provided hacking services to customers, including China’s Ministry of State Security and the People’s Liberation Army.

The victims named in the investigation include the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

QScan and QTRouter reportedly worked together to build and operate an obfuscation network that concealed the origin of malicious activity.

FBI Shuts Down China-Linked Hacking Platforms

QScan scanned the internet for vulnerable Internet of Things devices and automatically infected them. Compromised devices were then enrolled into the QTRouter network.

QTRouter combined infected IoT devices with commercial proxy services and leased virtual private servers. This setup allowed QTFY operators and other users to route malicious traffic through systems outside China.

As a result, attacks could appear to originate from compromised devices in other countries or even from systems located near the targeted network.

The DOJ said the seized domains were hard-coded into QScan and QTRouter malware. The domains supported essential malware functions, including communications and authentication.

By taking control of them through court-authorized seizures, investigators rendered the platforms inoperable. Attorney General Todd Blanche said the United States would use every available tool to stop state-sponsored hackers targeting critical infrastructure.

FBI Director Kash Patel described the action as the disruption of a global botnet and hacking platform used by Chinese state-sponsored actors to hide the origin of their attacks.

The operation continues a series of U.S. technical actions against PRC-linked infrastructure. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 infected U.S. computers in an operation tied to Mustang Panda.

In 2024, authorities disrupted a large IoT botnet allegedly operated by Flax Typhoon. A year earlier, the FBI disrupted Volt Typhoon infrastructure used to conceal attacks against U.S. and foreign critical infrastructure.

Alongside the disruption, the FBI and National Security Agency released a cybersecurity advisory containing indicators of compromise associated with QTFY activity dating back to at least 2018.

Lumen Technologies’ Black Lotus Labs also published technical research describing the group’s infrastructure-focused state-enablement model. The case highlights the continued use of insecure IoT devices, proxy networks, and rented virtual servers as tools for attribution evasion.

Organizations should review the newly released indicators, monitor outbound traffic for unusual proxy behavior, patch exposed devices, and restrict unnecessary internet access for IoT systems.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago