The U.S. Department of Justice announced Wednesday it has disrupted two hacking platforms operated by Chinese state-sponsored actors who successfully infiltrated NASA, the Federal Reserve, and multiple other federal agencies. The tools, called QScan and QTRouter, were run by a group known as QTFY that works for Nanjing Xinjiuwei Network Technology Company, which counts China's Ministry of State Security and People's Liberation Army among its clients. The platforms allowed hackers to hide their origins by routing attacks through compromised devices worldwide.

The intrusions hit a sweeping range of federal targets, including the Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate, according to the Justice Department's announcement. QTFY has been active since May 2018, Lumen Black Lotus Labs security researcher Damon Rouse told The Hacker News, with the digital quartermaster targeting victims "throughout the western world and beyond, especially with regard to academia." The group exploited both zero-day vulnerabilities—including three flaws in Ivanti CSA appliances discovered in 2024—and older weaknesses dating back to 2018 in products from Fortinet, Citrix, Microsoft Exchange Server, F5, Apache, Atlassian, Check Point, CrushFTP, and BeyondTrust. Attacks as recent as June 2026 targeted a U.S. election system.

"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," FBI Director Kash Patel said in the announcement. The FBI noted that QScan scans and automatically infects IoT devices worldwide before adding them to the QTRouter network, which combines compromised devices with commercial proxy services and leased virtual private servers to create an obfuscation layer. The bureau explained that this approach "enables QTFY-affiliated actors to blend in with legitimate users when targeting victim organizations." Lumen, which began working with the FBI on QTFY about a year ago, said the group particularly favored "hitting research communities given the collaborative nature of advanced science."

The platforms worked through a distributed architecture that made attribution nearly impossible. QScan identified vulnerable IoT devices and exploited them automatically, feeding the compromised machines into QTRouter's proxy network. That network authenticated to administration servers and used software called Clash to chain nodes together, mixing malicious traffic with legitimate activity on commercial proxy services. By routing attacks through nearby compromised IoT devices, hackers appeared to be local users rather than foreign intruders. The FBI's seizure of hard-coded domains caused both products to cease operations. The Justice Department described Nanjing as an enabling company that maintains business relationships with larger private Chinese cyber firms and employs former PLA members who leverage their contacts to win contracts focused on critical infrastructure targeting.

Lumen warned that the operation reveals "the high degree of industrialization occurring within China-nexus cyber operations," noting that state-sponsored actors have shifted from fragmented setups toward shared multi-tenant utility networks that deliver "anonymity and speed, and at a global scale." The research firm cautioned that because the infrastructure relies on legitimate paid subscriptions to commercial proxy services, "traditional static blocks are no longer sufficient to stop the threat." The FBI noted that QTFY actors participated in China-based freelance brokering networks to buy and sell cyber exploit items, including access to victim networks. The bottom line: infrastructure obfuscation networks that route attacks through commercial services and compromised consumer devices can't be blocked by IP address alone, forcing defenders to rethink detection from the ground up. Organizations that rely on perimeter defenses will need to invest in behavioral monitoring and assume that trusted geographic locations no longer guarantee legitimate traffic, while vendors of commercial proxy services face pressure to screen for state-sponsored abuse that hides in plain sight.