US Disrupts Chinese Hacking Tools Used Against Federal Agencies
The U.S. Department of Justice has dismantled Chinese state-backed hacking tools, QScan and QTRouter, allegedly used to compromise federal agencies including the Federal Reserve and DOJ.

The U.S. Department of Justice announced on Wednesday the successful disruption of sophisticated hacking tools, QScan and QTRouter, which were allegedly employed by Chinese state-sponsored actors since 2018. These tools, operated by the China-based Nanjing Xinjiuwei Network Technology Company, were primarily utilized by China’s Ministry of State Security and the People’s Liberation Army for cyber espionage and disruptive activities against sensitive U.S. networks.
According to an affidavit filed by the DOJ, the targeted agencies included a wide array of federal entities such as the Federal Reserve, the Department of Energy, the Department of Justice itself, the U.S. Senate, and NASA. The operation aimed to neutralize the infrastructure that facilitated these persistent cyber intrusions, which have been ongoing for several years.
QScan was designed to automatically scan and infect Internet of Things (IoT) devices globally, turning them into compromised nodes. QTRouter, on the other hand, functioned as an obfuscation network. This allowed malicious actors to mask the true origin of their attacks, making it appear as though the cyber operations were originating from the compromised IoT devices rather than from China.
The tools were allegedly used by a state-sponsored group identified as “QTFY,” which has been implicated in targeting U.S. critical infrastructure and other sensitive networks. The DOJ stated that QTFY exploited devices in over 130 countries. FBI Assistant Director Brett Leatherman highlighted that QTFY operates within a complex ecosystem of hackers-for-hire and government clients in China, with Nanjing Xinjiuwei reportedly selling stolen data and hacking services to Chinese military and intelligence agencies.
Investigators have been monitoring QTFY’s infrastructure since 2018, with the investigation continuing up to an attack on the U.S. Senate that occurred earlier this year. The affidavit detailed that other victims included the Department of Health and Human Services, the National Institutes of Health, numerous hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
The FBI and DOJ confirmed that the takedown rendered both QScan and QTRouter inoperable. This was achieved by seizing domains that were hard-coded into both platforms and were essential for critical functions such as communication and authentication. The FBI also noted that QTFY had customers outside of the Chinese government, indicating a broader reach for their services.
One of the earliest incidents investigated by the FBI involving this infrastructure was a 2019 attack at NASA, where hackers attempted to exploit a vulnerability in Pulse Secure VPN. Investigators successfully traced the IP addresses used in that attack back to locations and email addresses in China, providing early evidence of the actors' origins.
This operation is part of a broader effort by U.S. law enforcement to target and dismantle platforms used by state-backed hackers to obscure their cyberattacks. In recent years, the FBI has taken similar actions, including removing the PlugX surveillance malware from thousands of U.S. computers and disrupting multiple botnets associated with Chinese government hacking operations like Volt Typhoon and Flax Typhoon.
This operation specifically targeted and seized domains and infrastructure associated with the QScan and QTRouter platforms, which are attributed to the Chinese state-sponsored hacking group QTFY. The FBI detailed how these tools were used to scan for and exploit vulnerabilities, including CVE-2024-24919 in Check Point Quantum Gateway, and CVE-2019-11510 in Pulse Secure VPN, leading to the compromise of over 300 organizations. The infrastructure was also used to mask the origin of attacks against U.S. federal agencies and critical infrastructure.
The FBI's disruption of the QTFY infrastructure, including the QScan and QTRouter platforms, specifically targeted a Chinese state-sponsored group operating out of Nanjing Xinjiuwei Network Technology Company. This operation aimed to dismantle the tools used for espionage against U.S. critical infrastructure and sensitive networks, with victims including NASA, the Federal Reserve, and the Department of Energy. The FBI highlighted that QScan exploits IoT devices for botnets, while QTRouter uses these and leased servers to obfuscate malicious traffic, making attribution difficult.
The new reporting details the specific federal agencies targeted by the QTFY operation, including the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health. It also highlights that the group attempted to breach the U.S. Senate and a U.S. election system, and that its activities have been ongoing since at least 2018, with former Chinese military members involved.
The FBI's disruption of the QTFY group's QScan and QTRouter platforms provides further detail on the operational methods employed by this China-backed entity. Court documents reveal that QTFY actors include former members of the People's Liberation Army (PLA) and operate through a PRC private company, Nanjing Xinjiuwei, which receives payments from the Ministry of State Security (MSS). This new information clarifies the state-sponsored nature and organizational structure behind the hacking campaign.
The FBI and Department of Justice have announced the disruption of a China-linked hacking network by seizing domains associated with the QScan and QTRouter malware tools. These tools, developed by the QTFY group, were used to compromise U.S. government agencies, including NASA and the DOJ, for years. The operation involved disabling the malware's essential communication and authentication functions, rendering them inoperable. This action is part of a broader effort by U.S. law enforcement to dismantle state-sponsored cyber operations originating from the People's Republic of China.
The FBI and Department of Justice have seized domains for QScan and QTRouter, China-linked hacking platforms used by state-sponsored group QTFY to target NASA, federal agencies, and critical infrastructure. These platforms created an obfuscation network using compromised IoT devices and proxy services to hide the origin of malicious activity, disrupting a global botnet and highlighting the use of IoT devices for attribution evasion. The operation continues a series of U.S. technical actions against PRC-linked infrastructure, including past disruptions of PlugX, Flax Typhoon, and Volt Typhoon.
The US government has further detailed the disruption of the QTFY hacking platform, specifically targeting its QScan and QTRouter services. These tools were instrumental in scanning for vulnerable IoT devices and ensnaring them into a botnet to mask malicious activities. The FBI advisory also highlighted QTFY's active participation in exploit development communities and freelance hacker networks within China, and noted business relationships with entities linked to the Salt Typhoon cyberespionage group and the i-Soon firm.
The U.S. Department of Justice has issued a correction to its earlier statement, clarifying that several U.S. agencies, including NASA, the Federal Reserve, and the Department of Energy, were targeted by Chinese threat actors rather than being victimized. This update refines the narrative following last week's announcement detailing the alleged attacks, though the specific impact on the targeted agencies remains unspecified.