Chinese hackers linked by U.S. authorities to a state-sponsored operation targeted some of the federal government’s most sensitive institutions, including the Justice Department, Federal Reserve, NASA and U.S. Senate. Federal officials said the campaign relied on sophisticated infrastructure designed to identify vulnerable systems, conceal malicious traffic and maintain access to networks across the United States and overseas.
The Justice Department and FBI announced Aug. 26 that they had seized domains supporting two hacking platforms known as QScan and QTRouter, effectively disabling key infrastructure used by the operation. Officials linked the platforms to a China-based company called Nanjing Xinjiuwei Network Technology Company and said its customers included China’s Ministry of State Security and People’s Liberation Army.
The operation illustrates a growing national-security challenge for Washington. Cyberattacks against government agencies, defense contractors, telecommunications networks and other critical systems can create risks far beyond the theft of individual files, particularly when attackers develop the ability to remain inside networks or disguise the true origin of their traffic.
How Chinese Hackers Used QScan and QTRouter
Federal authorities identified the hacking group as QTFY, which the government says has operated since at least 2018. The NSA said QTFY developed a collection of malicious systems that could scan for vulnerable devices, exploit weaknesses and route hacking traffic through compromised infrastructure so attacks were harder to trace back to their origin.
QScan was designed to search the internet for weaknesses and exploit vulnerable Internet of Things devices and other exposed systems. QTRouter then provided an obfuscation network that allowed malicious traffic to appear as though it originated from elsewhere, giving attackers a way to blend into legitimate internet activity and complicate efforts by defenders to identify the source.
The NSA said the group used both zero-day vulnerabilities, which are previously unknown flaws, and known vulnerabilities that organizations may have failed to patch. QTFY operators also sought legitimate credentials after compromising systems, a method that can make an attacker appear more like an authorized user and allow continued access after an initial breach.
That technical model matters because it reduces the value of simply blocking traffic from known foreign addresses. If hackers can route operations through ordinary compromised devices in the United States or another country, network defenders must distinguish malicious activity from traffic that may appear routine.
Federal Agencies and Critical Networks Were Targeted
Court documents and federal statements identify an unusually broad collection of targets. The Justice Department named NASA, the Federal Reserve, Department of Energy, Justice Department, Department of Health and Human Services, National Institutes of Health and U.S. Senate among organizations targeted or affected by QTFY activity.
The distinction between successful intrusions and failed attempts is important. Federal court records cited in current reporting say hackers unsuccessfully attempted to access NASA networks in August 2019 and made unsuccessful attempts against the U.S. Senate and a U.S. hospital in March 2026, while other organizations suffered confirmed intrusions.
In September 2024, the hackers penetrated three unnamed Energy Department laboratories, NIH, an unnamed HHS agency and a U.S. security-device manufacturer, according to the affidavit. A joint federal cybersecurity advisory also described successful data theft in May 2024 from unnamed defense contractors, financial institutions and universities.
The breadth of those targets highlights why cybersecurity is now inseparable from national security. Government laboratories, financial institutions, defense companies and communications infrastructure can all provide intelligence value to an adversary, while access to critical systems could become significantly more dangerous during a geopolitical or military crisis.
Why the QTFY Campaign Matters
The Justice Department said seizing the domains was particularly disruptive because the addresses were hard-coded into QScan and QTRouter and were essential for functions such as communication and authentication. By taking control of that infrastructure, federal authorities said they rendered the two platforms inoperable rather than merely forcing the hackers to change a few servers.

The case also fits a broader pattern of U.S. operations against China-linked cyber infrastructure. Federal authorities said that in 2025 the FBI removed PlugX surveillance malware from more than 4,000 infected U.S. computers, while earlier operations disrupted botnets associated with Flax Typhoon and Volt Typhoon.
American News Brief has also examined how autonomous hacking risks can move from software testing into deception and real-world security threats. The QTFY case involves a different threat actor, but both developments show how quickly offensive cyber capabilities can scale when automation, compromised devices and hidden infrastructure are combined.
For policymakers, the central issue is not simply whether Washington can identify hackers after an intrusion. A more durable defense requires federal agencies and private operators of critical infrastructure to close known vulnerabilities quickly, isolate sensitive systems and reduce the number of internet-facing devices that provide attackers with easy entry points.
Beijing Rejects the U.S. Allegations
China disputes Washington’s characterization of its role in offensive cyber operations. A Chinese Embassy spokesperson said the government opposes cyberattacks and accused the United States of using cybersecurity concerns to discredit China and justify discriminatory restrictions on Chinese companies.
That denial is consistent with Beijing’s response to previous U.S. accusations involving other China-linked hacking groups. The disagreement leaves the two governments locked in a familiar pattern in which U.S. agencies publicly attribute cyber campaigns to Chinese actors while Beijing rejects the allegations and accuses Washington of politicizing cybersecurity.
The latest disruption nevertheless gives federal authorities something more concrete than public attribution. Rather than only issuing an advisory or sanctioning individuals, the government obtained court authorization to seize infrastructure that officials say the hackers required to operate their platforms.
The larger test will be whether those actions impose lasting costs. Cyber contractors can rebuild servers, create new malware and shift tactics, so the United States will need to continue combining technical disruption, aggressive patching, intelligence collection and legal action if it wants to reduce the ability of foreign adversaries to operate inside American networks.
U.S. Cyber Defense Faces a Long-Term Test
The QTFY operation demonstrates that Chinese hackers do not need to attack one spectacular target to create a major national-security problem. A sustained campaign against government agencies, research institutions, finance, defense contractors and critical infrastructure can produce intelligence advantages over years while creating hidden access that may become useful during a future confrontation.
The federal response shows that law enforcement and intelligence agencies are becoming more willing to dismantle hostile infrastructure instead of waiting for victims to defend themselves independently. That is an important shift, but it does not remove the responsibility of agencies and private companies to secure exposed systems before attackers gain a foothold.
America’s dependence on interconnected digital infrastructure makes cybersecurity a sovereignty issue as much as a technology problem. The government can seize domains and disrupt botnets, but long-term security will depend on whether public agencies and private operators close vulnerabilities faster than foreign cyber networks can exploit them.
