fbi2 articles
FBI Takes Down Chinese State Hacking Tools Used Against NASA, Senate, and DOE
The FBI has disrupted a botnet and seized two hacking platforms — QScan and QTRouter — used by a Chinese government-backed group called QTFY to infiltrate major US institutions, including NASA, the Department of Energy, the US Senate, and several other agencies, dating back to at least 2018. QTFY, operated through a private Chinese company called Nanjing Xinjiuwei, used the tools to build networks of compromised IoT devices that obscured the origin of their cyberattacks, exploiting critical vulnerabilities in products from Ivanti and Citrix. The seizure of three QTFY-linked domains has rendered both hacking services inoperable, marking the latest in a series of FBI actions targeting Chinese state-sponsored hacking operations.
Google and FBI Kneecap NetNut's 2 Million-Device Proxy Botnet
Google, the FBI, and other partners have significantly disrupted NetNut, a residential proxy network that had enrolled at least 2 million devices — mostly TV-streaming hardware — into a botnet used by cybercriminals to disguise malicious traffic as coming from ordinary homes and businesses. In a single week in June 2026, over 316 distinct threat clusters, including cybercriminal and espionage groups, were observed using NetNut exit nodes for activities such as password spraying and masking their origins. Researchers warn that lasting disruption is difficult, as proxy operators tend to simply buy capacity from competitors when their own networks are degraded, and call for broader, coordinated efforts involving ISPs and technology platforms.