
US says Chinese hackers breached Justice Dept., NASA, Federal Reserve, Senate
The Justice Department and FBI seized three domains Wednesday, shutting down two Chinese hacking platforms used against American government networks and critical infrastructure.
Court documents unsealed in the Southern District of California name the operators as QTFY, working for Nanjing Xinjiuwei Network Technology Co. Payments from China's Ministry of State Security to the firm indicate it conducts cyber operations for the government, the affidavit states. Some QTFY members are former People's Liberation Army personnel who leverage those relationships to win contracts supporting offensive operations.
The target list runs deep. Federal victims include NASA, the Federal Reserve, the Energy Department, the Justice Department, Health and Human Services, the National Institutes of Health, and, in 2026, the Senate. Hospitals, telecom providers, power companies, financial institutions and defense contractors were also hit.
The two tools worked together. QScan carried a library of more than 200 exploits and processed over two million scanning tasks in a single day in 2024. After exploiting a Check Point vulnerability days after its public disclosure, QTFY stole server configuration files and user account details from more than 300 US organizations.
QTRouter handled concealment, routing traffic through hacked internet-connected devices, leased servers and commercial proxies, often through machines geographically local to the victim so the intrusions blended in with legitimate users.
One Ohio medical center, targeted in August 2020, sent a complaint to the hosting provider that read: "Attacking healthcare in a pandemic is just wrong."
The seized domains were hard-coded into both tools, leaving them inoperable. QTFY paid for them from China using PayPal accounts tied to an Agricultural Bank of China debit card and Alipay, transfers that form the basis of the money laundering charges.