FBI disables China-linked hacking tools used against US agencies

kritsapong jieantaratip/Getty Images
A hacking group used the tools to target networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services.
The FBI seized three internet domains Wednesday that prosecutors say Chinese government-backed hackers used to target U.S. agencies, critical infrastructure and other networks.
The Justice Department attributed the tools, known as QScan and QTRouter, to a hacking group called QTFY. Court records say the group operates through Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services to China’s main civilian intelligence agency and its military.
The group targeted networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the Energy, Justice and Health and Human Services departments, according to an FBI affidavit. Hospitals, telecommunications providers, power companies, banks and defense contractors were also targeted.
The filing does not say that every attempted attack succeeded. A 2019 attempt against NASA, for example, failed because the agency had already fixed the security flaw the hackers tried to exploit.
China’s embassy in Washington, D.C. did not immediately respond to a request for comment. Chinese officials have repeatedly denied Beijing sponsors hacking operations against the United States.
QScan was used to look for weak spots while QTRouter helped the hackers hide. QScan searched the internet for vulnerable systems and tried to break into them. QTRouter sent the hackers’ traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers. The setup was meant to make the activity appear to come from somewhere other than China.
QScan carried code for more than 200 different attacks and could work on a massive scale. On one day in 2024, it processed more than 2 million scanning or exploitation tasks, according to the affidavit.
Lumen Technologies, which tracked the same infrastructure for roughly a year, described the operator as an “infrastructure quartermaster” that provided other China-linked hackers with a ready-made service for finding targets and hiding their tracks. Lumen said networks first examined by QScan were later seen communicating through the group’s concealed network, suggesting some operations had moved from scouting targets toward attempts to break in. The system also mixed malicious traffic with that of ordinary internet users, making it harder to spot and block.
“These tools were used by PRC cyber actors to hide the origin of their attacks,” FBI Director Kash Patel said Wednesday.
Investigators said QTFY could take advantage of newly discovered security flaws quickly and at a large scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations, according to court documents.
Several months later, the hackers allegedly used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.
Investigators also tied the group’s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea and an insurance organization in Missouri.
The case highlights how Chinese intelligence and military agencies continue to heavily rely on private companies for cyber operations and services.
Wednesday’s announcement follows years of similar FBI operations against Chinese hacking infrastructure. The bureau last year removed PlugX surveillance malware from more than 4,200 U.S. computers infected by another state-backed hacking group.
Federal authorities have also dismantled a network of compromised routers, cameras and other devices associated with Flax Typhoon and disrupted a separate network used by prominent Chinese hacking collective Volt Typhoon to hide attacks against U.S. critical infrastructure.




