Page 1 of 1

How China-Linked Hackers Targeted NASA, US DoJ and Senate

Posted: 29 Aug 2026, 16:33
by Mexico_b
The US seized domains of Chinese threat actors targeting the US, as Rob Nidschelm of Getronics warns it should not be mistaken for permanent neutralisation
Critical infrastructure is constantly under attack, as proven by the recent announcement by the US Justice Department and the FBI, uncovering a massive Chinese hacking operation with a long list of high-value targets.

Court documents which were unsealed in the Southern District of California, reveal that a Chinese state-sponsored group called QTFY was behind hacking attempts of critical US institutions including NASA, Federal Reserve, Department of Energy (DoE), Department of Justice (DoJ), Department of Health and Human Services, National Institutes of Health (NIH) and the US Senate.

While not all QTFY intrusions were successful, court documents show that in September 2024, QTFY actors successfully compromised three DOE National Laboratories, the NIH and a US security-device manufacturer using zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA).

QTFY, according to the DoJ, is employed by a company called Nanjing Xinjiuwei Network Technology which is based in China. The company did not respond to Reuters' request for comment.

They created and operated two hacking platforms QScan and QTRouter – the domains of both were seized by the Justice Department.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure,” FBI Director Kash Patel said in the DoJ release announcing the incident.

“These tools were used by People’s Republic of China (PRC) cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division and DOJ partners, we seized adversary infrastructure and shut these platforms down.”

Who are QTFY and what are QScan and QTRouter?
QTFY is known to offer hacking services to its customers. The DoJ says that PRC’s Ministry of State Security and the People’s Liberation Army are among these paying customers.

QScan and QTRouter were among the offerings for sale.

As the name suggests, QScan is the tool that scans for IoT devices worldwide. It then “automatically infects” thousands of them.

These compromised devices are then added to the QTRouter network of QTFY-controlled devices.

QTRouter contains commercial proxy service devices and leased virtual private servers in addition to the compromised devices.

What makes QScan and QTRouter significant is not simply the list of organisations targeted, but the industrialisation of state-aligned cyber operations

Rob Nidschelm, Global Head of Operational Security at Getronics
It then serves as the “obfuscation network” – to throw off defenders by hiding the “PRC-origin of their computer intrusion activities”.

The DoJ says that it looked like the malicious communications appeared to originate from the compromised computers – like the ones compromised by QScan.

“Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law,” a spokesperson for the Chinese Embassy in Washington told Reuters, adding that US uses cybersecurity to “smear or discredit China”.

Industrialised state-sponsored operations
“What makes QScan and QTRouter significant is not simply the list of organisations targeted, but the industrialisation of state-aligned cyber operations,” says Rob Nidschelm, Global Head of Operational Security at Getronics.

“One platform identified and exploited exposed systems at scale, while the other routed activity through compromised IoT devices and commercial proxies, making hostile traffic appear local and legitimate.”

The US DoJ says that both the seized domains were hard-coded into the hacking platforms – QScan and QTRouter.The domains were used for essential tasks like communication and authentication. As a result, the court-authorised seizures have made QScan and QTRouter inoperable.

“The domain seizures represent a meaningful disruption because they removed shared infrastructure that could support multiple operators,” Rob notes.

“However, this should not be mistaken for permanent neutralisation. Organisations still need to patch edge devices quickly, examine historical telemetry and investigate unsuccessful access attempts.

“It is also important to distinguish targeting from a successful breach. The public evidence confirms serious intrusions, but it also shows that the cited attempts against NASA and the US Senate were unsuccessful.”


source : https://cybermagazine.com/news/how-chin ... and-senate