US Disrupts Chinese Hacking Tools Used Against Federal Agencies
The U.S. Department of Justice has dismantled Chinese state-backed hacking tools, QScan and QTRouter, allegedly used to compromise federal agencies including the Federal Reserve and DOJ.

The U.S. Department of Justice announced on Wednesday the successful disruption of sophisticated hacking tools, QScan and QTRouter, which were allegedly employed by Chinese state-sponsored actors since 2018. These tools, operated by the China-based Nanjing Xinjiuwei Network Technology Company, were primarily utilized by China’s Ministry of State Security and the People’s Liberation Army for cyber espionage and disruptive activities against sensitive U.S. networks.
According to an affidavit filed by the DOJ, the targeted agencies included a wide array of federal entities such as the Federal Reserve, the Department of Energy, the Department of Justice itself, the U.S. Senate, and NASA. The operation aimed to neutralize the infrastructure that facilitated these persistent cyber intrusions, which have been ongoing for several years.
QScan was designed to automatically scan and infect Internet of Things (IoT) devices globally, turning them into compromised nodes. QTRouter, on the other hand, functioned as an obfuscation network. This allowed malicious actors to mask the true origin of their attacks, making it appear as though the cyber operations were originating from the compromised IoT devices rather than from China.
The tools were allegedly used by a state-sponsored group identified as “QTFY,” which has been implicated in targeting U.S. critical infrastructure and other sensitive networks. The DOJ stated that QTFY exploited devices in over 130 countries. FBI Assistant Director Brett Leatherman highlighted that QTFY operates within a complex ecosystem of hackers-for-hire and government clients in China, with Nanjing Xinjiuwei reportedly selling stolen data and hacking services to Chinese military and intelligence agencies.
Investigators have been monitoring QTFY’s infrastructure since 2018, with the investigation continuing up to an attack on the U.S. Senate that occurred earlier this year. The affidavit detailed that other victims included the Department of Health and Human Services, the National Institutes of Health, numerous hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
The FBI and DOJ confirmed that the takedown rendered both QScan and QTRouter inoperable. This was achieved by seizing domains that were hard-coded into both platforms and were essential for critical functions such as communication and authentication. The FBI also noted that QTFY had customers outside of the Chinese government, indicating a broader reach for their services.
One of the earliest incidents investigated by the FBI involving this infrastructure was a 2019 attack at NASA, where hackers attempted to exploit a vulnerability in Pulse Secure VPN. Investigators successfully traced the IP addresses used in that attack back to locations and email addresses in China, providing early evidence of the actors' origins.
This operation is part of a broader effort by U.S. law enforcement to target and dismantle platforms used by state-backed hackers to obscure their cyberattacks. In recent years, the FBI has taken similar actions, including removing the PlugX surveillance malware from thousands of U.S. computers and disrupting multiple botnets associated with Chinese government hacking operations like Volt Typhoon and Flax Typhoon.
This operation specifically targeted and seized domains and infrastructure associated with the QScan and QTRouter platforms, which are attributed to the Chinese state-sponsored hacking group QTFY. The FBI detailed how these tools were used to scan for and exploit vulnerabilities, including CVE-2024-24919 in Check Point Quantum Gateway, and CVE-2019-11510 in Pulse Secure VPN, leading to the compromise of over 300 organizations. The infrastructure was also used to mask the origin of attacks against U.S. federal agencies and critical infrastructure.
The FBI's disruption of the QTFY infrastructure, including the QScan and QTRouter platforms, specifically targeted a Chinese state-sponsored group operating out of Nanjing Xinjiuwei Network Technology Company. This operation aimed to dismantle the tools used for espionage against U.S. critical infrastructure and sensitive networks, with victims including NASA, the Federal Reserve, and the Department of Energy. The FBI highlighted that QScan exploits IoT devices for botnets, while QTRouter uses these and leased servers to obfuscate malicious traffic, making attribution difficult.