FBI Dismantles China-Linked Hacking Infrastructure Targeting US Critical Infrastructure
Key Takeaways The U.S. Justice Department and FBI have dismantled two China-linked hacking platforms, QScan and QTRouter. These platforms were allegedly used by a state-sponsored group, QTFY, to...
Key Takeaways
- The U.S. Justice Department and FBI have dismantled two China-linked hacking platforms, QScan and QTRouter.
- These platforms were allegedly used by a state-sponsored group, QTFY, to target critical U.S. infrastructure, including federal agencies and NASA.
- The operation involved seizing domains crucial to the malware’s functionality, rendering the hacking infrastructure inoperable.
- Organizations are urged to review new indicators of compromise and implement mitigation strategies for IoT devices and network traffic.
FBI Disrupts China-Backed Hacking Operations Targeting U.S. Infrastructure
In a significant cybersecurity action, the U.S. Department of Justice and the Federal Bureau of Investigation have announced the seizure of domains associated with two sophisticated China-linked hacking platforms, QScan and QTRouter. These platforms are accused of facilitating cyber espionage against sensitive U.S. networks, including those belonging to federal agencies and critical infrastructure operators like NASA.
Table Of Content
Unsealed court documents from the Southern District of California connect this malicious infrastructure to a state-sponsored entity from the People’s Republic of China, identified as QTFY. This group is reportedly affiliated with Nanjing Xinjiuwei Network Technology Company, a firm allegedly providing hacking services to various clients, including China’s Ministry of State Security and the People’s Liberation Army.
Targets and Tactics: Unmasking QScan and QTRouter
The extensive list of victim organizations cited in the investigation underscores the breadth of the threat, encompassing the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and even the U.S. Senate.
QScan and QTRouter functioned in tandem to create and manage an elaborate obfuscation network designed to conceal the true origin of cyberattacks. QScan’s primary role involved scanning the internet for vulnerable Internet of Things (IoT) devices, subsequently infecting them and enrolling them into the QTRouter network.
QTRouter then leveraged these compromised IoT devices, alongside commercial proxy services and leased virtual private servers, to route malicious traffic. This sophisticated setup allowed QTFY operators and their clients to mask their activities, making it appear as though attacks originated from various global locations or even from systems geographically close to the intended targets, thereby complicating attribution efforts.
The DOJ said that the seized domains were hard-coded into the QScan and QTRouter malware, providing essential services such as command-and-control communications and authentication. By gaining control of these critical domains through court-authorized seizures, U.S. investigators effectively rendered the entire hacking infrastructure inoperable.
Attorney General Todd Blanche emphasized the U.S. government’s commitment to deploying all available resources to counter state-sponsored hacking campaigns targeting critical infrastructure. FBI Director Kash Patel characterized the operation as a successful disruption of a global botnet and hacking platform utilized by Chinese state-sponsored actors to obscure their attack origins.
A Pattern of Disruption Against PRC-Linked Threats
This latest action builds upon a series of aggressive technical operations undertaken by the U.S. against infrastructure linked to the People’s Republic of China. Notably, in 2025, the FBI removed PlugX surveillance malware from over 4,000 infected U.S. computers in an operation connected to the Mustang Panda group. In 2024, authorities dismantled a large IoT botnet believed to be operated by Flax Typhoon. A year prior, the FBI had disrupted Volt Typhoon infrastructure, which was similarly used to hide attacks against critical infrastructure in the U.S. and abroad.
Coinciding with the disruption, the FBI and National Security Agency (NSA) issued a joint cybersecurity advisory containing indicators of compromise (IoCs) associated with QTFY activity, tracing back to at least 2018. Further technical research by Lumen Technologies’ Black Lotus Labs also shed light on the group’s infrastructure-focused state-enablement model, highlighting the persistent use of insecure IoT devices, proxy networks, and rented virtual servers for attribution evasion.
What You Should Do
- Review Indicators of Compromise: Immediately review the newly released IoCs from the FBI and NSA and implement them into your network defenses.
- Monitor Outbound Traffic: Increase scrutiny on outbound network traffic for any unusual proxy behavior or connections to known malicious IP addresses.
- Patch Exposed Devices: Ensure all Internet of Things (IoT) devices and other internet-facing systems are fully patched and updated to the latest secure versions.
- Restrict IoT Access: Implement strict network segmentation and restrict unnecessary internet access for IoT systems to minimize their attack surface.
- Implement Strong Authentication: Enforce multi-factor authentication (MFA) across all critical systems and accounts to prevent unauthorized access.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.