U.S. Disrupts China-Linked Hacking Network Behind Agency Breaches
U.S. authorities seized domains supporting two China-linked hacking platforms after breaches affected the Federal Reserve, NASA, the Senate and other sensitive networks. The action disrupts attack infrastructure, but officials have not disclosed the full damage.

A takedown built around two domains
The Justice Department said Wednesday that court-authorized seizures disabled domains supporting QScan and QTRouter, two platforms tied to a Chinese state-sponsored hacking group. Federal filings identified the Federal Reserve, NASA, the Senate and the Justice Department among institutions breached, alongside the Energy and Health and Human Services departments and the National Institutes of Health.cnbc +1
The operation targeted infrastructure used by a group known as QTFY, which U.S. authorities say worked through Nanjing Xinjiuwei Network Technology Company. Court documents say the company’s customers included China’s Ministry of State Security and People’s Liberation Army, while the affected networks extended beyond government to hospitals, telecommunications providers, power companies, financial institutions and defense contractors.cnbc +1
An infection pipeline designed to hide its users
QScan was used to find and automatically compromise vulnerable internet-connected devices, according to the Justice Department’s account. Those devices then fed QTRouter, a wider network that also incorporated commercial proxy equipment and leased virtual private servers, allowing operators and customers to obscure where attacks originated.itpro
The seized domains were hard-coded into the malware, giving investigators a point of leverage against both platforms. Authorities said the underlying infrastructure had supported compromises in the United States and abroad since at least 2018, and an affidavit listed four unnamed companies in the United States and South Korea among victims.dailysabah +1
Disruption does not settle the damage
Officials have not publicly detailed what information was taken, how long intruders remained inside individual agencies or whether every compromised system has been cleared. The Justice Department’s action blocks infrastructure and may help defenders identify infections, but it does not by itself answer the larger counterintelligence questions created by access to monetary-policy, space, health and legislative networks.cnbc +1
The case also illustrates Washington’s growing focus on the private contractors that support Chinese cyber operations. China has repeatedly denied U.S. hacking allegations, and its embassy in Washington did not immediately respond to requests for comment on the latest action.dailysabah +1 For network defenders, the immediate task is narrower: find devices enlisted into the proxy system, remove any persistence left behind and watch for the operators to rebuild with fresh domains or infrastructure.