FBI Disables Chinese Hacking Platforms Targeting U.S. Agencies
FBI seized domains on Aug. 26 to disable QScan and QTRouter, platforms used to find vulnerable devices and mask attacks on NASA, the Federal Reserve and other U.S. agencies.
Federal authorities seized internet domains on Aug. 26 to disable QScan and QTRouter, two interconnected hacking platforms, the Justice Department and FBI said. The seizures removed three domains that were hard-coded into the platforms and broke their command-and-control functions, rendering the systems inoperable.
Court filings and a joint advisory from the FBI, the National Security Agency and the Cyber National Mission Force describe QScan as an automated reconnaissance and exploitation tool with more than 200 proof-of-concept exploits. The advisory says the tool handled millions of scanning and penetration tasks, including more than two million operations recorded on a single day in 2024.
QScan automatically searched for and compromised internet-connected devices and enrolled them into QTRouter. QTRouter then routed malicious traffic through those hacked machines together with commercial proxy services and leased virtual private servers, making the traffic appear to come from locations near targeted networks.
Federal filings link the platforms to QTFY, operated by Nanjing Xinjiuwei Network Technology Company. The filings allege QTFY sold services to customers that included China’s Ministry of State Security and elements of the People’s Liberation Army. U.S. officials said a May 2024 campaign tied to the infrastructure exfiltrated data from more than 300 organizations worldwide.
The Justice Department identified several U.S. targets of the tools, including NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.
In a statement, Attorney General Todd Blanche wrote that federal law enforcement ‘investigated and disabled the PRC’s malicious software,’ and framed the action as part of a series of operations against state-sponsored hacking. FBI Director Kash Patel described the seizure as ‘the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure’ and said the tools were used to hide the origin of attacks.
Officials noted that compromised routers and other internet-of-things devices have been used in both state-backed operations and financially motivated crime. Authorities previously dismantled a proxy network of about 369,000 hacked devices across 163 countries that was used in cryptocurrency thefts, bank fraud and ransomware and reportedly generated more than $5.7 million for its operators.
The domain seizures follow other court-authorized operations targeting foreign cyber infrastructure. In January 2025, authorities removed PlugX surveillance malware from roughly 4,258 infected U.S. systems tied to a group known as Mustang Panda. The government also disrupted Flax Typhoon infrastructure in 2024 and Volt Typhoon in 2023. An Aug. 12 presidential memorandum directed creation of a federally supervised cyber disruption program and gave officials 60 days to set eligibility standards, target-review procedures and safeguards.
Technology companies coordinated with the Justice Department on separate operations. In May, participants interrupted more than 1.4 million scam-linked accounts, blocked malicious traffic, decommissioned hosting services and helped freeze more than $3.8 million in cryptocurrency.
Federal officials warned that individual users can still face threats from malware and compromised devices used as part of larger operations. Recommended protections include keeping software and router firmware up to date, avoiding suspicious downloads and verifying websites before entering passwords or other sensitive information.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








