← BACK TO FEED
ChinaFBIcybersecuritystate-sponsored hackingbotnet

FBI Takes Down Chinese State Hacking Tools Used Against NASA, Senate, and DOE

The FBI has disrupted a botnet and seized two hacking platforms — QScan and QTRouter — used by a Chinese government-backed group called QTFY to infiltrate major US institutions, including NASA, the Department of Energy, the US Senate, and several other agencies, dating back to at least 2018. QTFY, operated through a private Chinese company called Nanjing Xinjiuwei, used the tools to build networks of compromised IoT devices that obscured the origin of their cyberattacks, exploiting critical vulnerabilities in products from Ivanti and Citrix. The seizure of three QTFY-linked domains has rendered both hacking services inoperable, marking the latest in a series of FBI actions targeting Chinese state-sponsored hacking operations.

The FBI has seized two hacking platforms and disrupted a botnet linked to a Chinese government-backed group that spent years quietly burrowing into some of America's most sensitive networks. Among the confirmed victims: NASA, the US Senate, the Department of Energy, the Federal Reserve, the Department of Justice, the National Institutes of Health, and the Department of Health and Human Services.

The two tools at the centre of this are QScan, a piece of malware that automatically finds and infects IoT devices to build out a botnet, and QTRouter, which chains those compromised devices together with commercial proxy servers and leased VPS infrastructure to form an obfuscation network. The idea is straightforward: route your intrusions through thousands of hijacked kettles and routers worldwide, and your traffic looks local. Attribution becomes a nightmare.

The group behind both tools is identified in court documents as QTFY, operated by a private Chinese company called Nanjing Xinjiuwei. The FBI says payments from China's Ministry of State Security to Nanjing Xinjiuwei make it fairly clear whose interests the company is actually serving. Several QTFY members are former People's Liberation Army personnel, and the documents suggest those connections were actively used to land offensive cyber contracts.

On Monday, a US federal court approved seizure warrants for three domains hardcoded directly into the QScan and QTRouter malware: qtproxy.xyz, qt-proxy.org, and qt-team.com. Pulling those domains killed both services.

QTFY has been at this since at least 2018. The FBI traced one early incident to August 2019, when the group attempted to compromise NASA by exploiting CVE-2019-11510, a critical flaw in Ivanti's Pulse Secure VPN that let attackers harvest valid credentials from vulnerable systems. Ivanti had already patched it by then. That particular vulnerability also turned up in Chinese intrusions against defence contractors and financial institutions across the US and beyond, as reported at the time.

The same CVE was repurposed in 2020 to hit a medical centre in Ohio during the pandemic. Other targets that year included financial firms in Michigan and South Korea, plus a Missouri insurance agency, which was breached via CVE-2019-19781, a Citrix VPN flaw enabling unauthenticated remote code execution.

More recently, in 2024, QTFY compromised computers at three DOE National Laboratories, NIH, and a US security hardware manufacturer using a zero-day in Ivanti's Cloud Services Appliance. The US Senate compromise also appears to have occurred recently, though the exact timeline is thin on detail in the public documents.

The FBI declined to answer questions about the total scale of the compromise or whether QTFY overlaps with any of China's publicly named Typhoon-branded threat groups.

This seizure sits within a broader pattern. Earlier in 2025, the FBI scrubbed PlugX malware from over 4,000 US machines after action against Mustang Panda. In 2024, Flax Typhoon torched their own botnet of hundreds of thousands of devices when US authorities closed in. Before that, the FBI dismantled a Volt Typhoon botnet being used to target critical infrastructure at home and abroad.

It is, at this point, a fairly predictable cycle. The feds disrupt something, the groups rebuild, and another court order follows a year or two later. Whac-a-mole with state-backed hackers and essentially unlimited resources on the other side.

READ NEXT
China Opens Security Probe Into Palo Alto Networks — And Tells Us Absolutely Nothing About WhyGoogle and FBI Kneecap NetNut's 2 Million-Device Proxy BotnetBadBox Botnet Comes for Your Car: First Malware Targeting Vehicle Head Units Discovered