The FBI on Wednesday disrupted a botnet and seized two hacking platforms that Chinese government operatives used to break into NASA, the US Senate, the Department of Energy, and multiple other federal agencies and critical infrastructure networks. The tools — a vulnerability scanning malware called QScan and an obfuscation network named QTRouter — also targeted the Federal Reserve, Department of Justice, Department of Health and Human Services, and the National Institutes of Health. According to court documents, a group called QTFY created and ran both platforms, working for a private Chinese company named Nanjing Xinjiuwei that receives payments from China's Ministry of State Security to carry out malicious cyber operations on behalf of the government.

The hacking infrastructure has been active since at least 2018 and continued attacking American targets as recently as this year, when QTFY compromised the US Senate. In August 2019, the FBI investigated an attempted breach at NASA where Chinese operatives tried to exploit a critical vulnerability in Ivanti's Pulse Secure VPN that let attackers steal legitimate users' passwords and gain unauthorized network access. QTFY later used this same flaw in 2020 to attack an Ohio medical center during the COVID-19 pandemic. Other victims in 2019 and 2020 included financial institutions in Michigan and South Korea and a Missouri insurance agency, which was hit through a separate critical vulnerability in Citrix VPN products. In 2024, QTFY hackers broke into computers at three Department of Energy National Laboratories, the National Institutes of Health, and a US security device manufacturer through a zero-day attack against Ivanti Cloud Services Appliance.

Court documents describe how QScan works: it scans and automatically infects thousands of internet-connected devices around the world, then adds them to the QTRouter network of QTFY-controlled machines. The QTRouter botnet — made up of these hijacked devices plus commercial proxy service equipment and rented virtual private servers — functions as an obfuscation layer that lets QTFY and other criminals who pay for access hide where their attacks are coming from, making the intrusions look like they're originating from local computers. On Monday, a federal court granted seizure warrants for three domains hardcoded into the malware: qtproxy.xyz, qt-proxy.org, and qt-team.com. The court-authorized seizures made both hacking services stop working, the Justice Department said.

This disruption follows several FBI operations aimed at stopping Chinese government hacking over recent years. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 US computers infected by the China-sponsored group Mustang Panda. A year earlier, China's Flax Typhoon destroyed their own botnet of hundreds of thousands of infected internet-of-things devices when confronted by federal investigators. In late 2023, the FBI took down a botnet used by another Chinese government crew, Volt Typhoon, to attack US and foreign critical infrastructure. However, in June, Lumen's Black Lotus Labs reported a "significant resurgence" of a Volt Typhoon-linked botnet, with the cluster of compromised machines surging to 1,500 infected routers and IoT devices. Court documents note that QTFY actors include former members of China's People's Liberation Army who use their military relationships to win contracts and subcontracts supporting offensive cyber operations. The recurring pattern suggests federal authorities face a persistent challenge: dismantling infrastructure only to see threat actors rebuild or shift tactics. While seizures can temporarily blind adversaries, the underlying incentive structure for state-sponsored hacking remains intact, and attribution alone rarely changes the calculus for operators who enjoy legal immunity in their home countries.