Trending

    FBI and DOJ Seize Chinese Proxy Platforms Used for State-Sponsored Espionage

    Section editor: ·Moderate10 articles covering this·10 news sources·Updated an hour ago·World
    Share:
    Infographic showing the disruption of QTFY's proxy platforms by the FBI and its implications for cybersecurity.

    Here's what it means for you.

    If you work in cybersecurity or critical infrastructure, this operation signals a heightened focus on countering state-sponsored threats.

    Why it matters

    The disruption of QScan and QTRouter highlights the ongoing battle against cyber espionage, particularly from state-sponsored actors like China.

    What happened (in 30 seconds)

    • On August 26, 2026, the DOJ and FBI announced the seizure of domains linked to QScan and QTRouter, platforms used for espionage.
    • Nanjing Xinjiuwei, the operator, provided services to Chinese state entities, facilitating attacks against U.S. agencies since at least 2018.
    • The operation aimed to degrade the group's ability to mask their cyber activities through compromised devices.

    The context you actually need

    • Chinese state-sponsored cyber operations have increasingly utilized private contractors for infrastructure, complicating attribution and response.
    • QTFY's platforms were integral in obscuring the origins of attacks, evolving from IoT botnets to co-opting VPN services.
    • This disruption follows previous actions against groups like Volt Typhoon, indicating a sustained U.S. strategy to counteract Chinese cyber threats.

    What's really happening

    On August 26, 2026, the U.S. Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) executed a significant cyber disruption operation against QScan and QTRouter, two proxy and scanning platforms operated by Nanjing Xinjiuwei Network Technology Company. These platforms were integral to the Chinese state-sponsored group QTFY, which has been linked to espionage campaigns targeting U.S. government agencies and critical infrastructure since at least 2018.

    The operation involved the seizure of three domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—hardcoded into the QScan and QTRouter systems. QScan was designed to scan for and exploit vulnerabilities in Internet of Things (IoT) devices, effectively building botnets that could be used for various malicious activities. Meanwhile, QTRouter facilitated the routing of malicious traffic through compromised devices and proxies, further obscuring the origins of cyberattacks.

    The implications of this operation are significant. By disrupting these platforms, the DOJ and FBI aim to degrade the capabilities of QTFY, making it more challenging for them to conduct espionage without detection. This is particularly relevant given that QTFY has been linked to attacks against high-profile U.S. entities, including NASA, the Federal Reserve, and the Department of Energy. In 2024 alone, QScan processed over 2 million scanning and exploit tasks, underscoring the scale of its operations.

    The broader context reveals a pattern of Chinese state-sponsored cyber operations increasingly relying on private contractors for infrastructure and tools. This trend complicates the attribution of cyberattacks and poses challenges for international cybersecurity efforts. The U.S. has been ramping up its countermeasures against these threats, as evidenced by this operation and previous disruptions of groups like Volt Typhoon.

    Despite the success of this operation, experts anticipate that QTFY will adapt and pivot to new infrastructure, indicating that the threat landscape will continue to evolve. The Chinese Ministry of Foreign Affairs has denied the allegations, labeling them as false information, which reflects the ongoing geopolitical tensions surrounding cyber operations.

    Who feels it first (and how)

    • Cybersecurity professionals: Increased scrutiny and demand for advanced defenses against state-sponsored threats.
    • Government agencies: Heightened awareness and potential resource allocation for cybersecurity measures.
    • Private sector companies: Those in critical infrastructure may face increased regulatory pressure to bolster defenses.

    What to watch next

    • New infrastructure developments: Monitor for signs of QTFY or similar groups adapting their operations to new platforms.
    • Legislative changes: Watch for potential new cybersecurity regulations aimed at enhancing defenses against state-sponsored threats.
    • International responses: Observe how other nations, particularly allies, react to U.S. actions against Chinese cyber operations.
    Known:

    The DOJ and FBI successfully disrupted QScan and QTRouter, rendering them inoperable.

    Likely:

    QTFY will pivot to new infrastructure to continue its operations.

    Unclear:

    The long-term impact on U.S.-China relations regarding cybersecurity and espionage.

    Frequently Asked Questions

    Why it matters?
    The disruption of QScan and QTRouter highlights the ongoing battle against cyber espionage, particularly from state-sponsored actors like China.
    What happened (in 30 seconds)?
    On August 26, 2026, the DOJ and FBI announced the seizure of domains linked to QScan and QTRouter, platforms used for espionage. Nanjing Xinjiuwei, the operator, provided services to Chinese state entities, facilitating attacks against U.S. agencies since at least 2018. The operation aimed to degrade the group's ability to mask their cyber activities through compromised devices.
    What's really happening?
    On August 26, 2026, the U.S. Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) executed a significant cyber disruption operation against QScan and QTRouter, two proxy and scanning platforms operated by Nanjing Xinjiuwei Network Technology Company. These platforms were integral to the Chinese state-sponsored group QTFY, which has been linked to espionage campaigns targeting U.S. government agencies and critical infrastructure since at least 2018. The operation involved th
    Who feels it first (and how)?
    Cybersecurity professionals: Increased scrutiny and demand for advanced defenses against state-sponsored threats. Government agencies: Heightened awareness and potential resource allocation for cybersecurity measures. Private sector companies: Those in critical infrastructure may face increased regulatory pressure to bolster defenses.
    What to watch next?
    New infrastructure developments: Monitor for signs of QTFY or similar groups adapting their operations to new platforms. Legislative changes: Watch for potential new cybersecurity regulations aimed at enhancing defenses against state-sponsored threats. International responses: Observe how other nations, particularly allies, react to U.S. actions against Chinese cyber operations.
    10 Articles
    Okaz

    واشنطن تعلن إحباط حملة قرصنة صينية استهدفت مؤسسات حكومية أمريكية حساسة

    The United States has announced the thwarting of a significant cyber-espionage campaign attributed to Chinese entities, targeting sensitive government institutions including the Department of Justice, NASA, and the Federal Reserve. The Justice Depart...

    12 hours ago
    Read Full Article
    Al Jazeera

    US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

    U.S. authorities have reported that Chinese-linked hackers have targeted sensitive government networks, including NASA and the Senate, since 2018. The U.S. Justice Department has seized two domains allegedly used in these cyberattacks, which are part...

    Al Jazeera

    US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

    U.S. authorities have reported that Chinese-linked hackers have targeted sensitive government networks, including NASA and the Senate, since 2018. The U.S. Justice Department has seized two domains allegedly used in these cyberattacks, which are part...

    The Hill

    NASA, Fed, Senate among Chinese hackers' targets, Justice Department says

    The U.S. Department of Justice announced the disruption of a Chinese hacking operation that targeted sensitive agencies, including NASA, the Federal Reserve, and the U.S. Senate. The DOJ seized two hacking platforms, QScan and QTRouter, linked to the...

    The Washington Times

    'Hackers for hire': How a Chinese group hid its attacks on U.S. infrastructure

    Federal agents have dismantled two hacking platforms linked to a Chinese state-sponsored group that concealed cyberattacks on U.S. infrastructure, targeting sensitive entities such as the Justice Department, NASA, and the U.S. Senate. This action hig...

    WIRED

    FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

    The FBI has disrupted a sophisticated hacking campaign orchestrated by Chinese actors, targeting multiple U.S. agencies, including NASA, the Federal Reserve, and the Justice Department. This operation utilized proxy tools to facilitate mass hacking e...

    TechCrunch

    US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate

    The U.S. Department of Justice has successfully seized domains associated with a Chinese botnet that was involved in hacking operations targeting NASA, the Justice Department, and the Senate. This action rendered the botnet and its command and contro...

    Global News

    U.S. says Chinese hackers accessed DOJ, NASA, other sensitive agencies

    The U.S. Justice Department announced that it has seized domains linked to two hacking platforms allegedly involved in a campaign that targeted several sensitive agencies, including the Department of Justice, NASA, and the U.S. Federal Reserve. This ...

    Global News

    U.S. says Chinese hackers accessed DOJ, NASA, other sensitive agencies

    The U.S. Justice Department announced that it has seized domains linked to two hacking platforms allegedly involved in a campaign that targeted several sensitive agencies, including the Department of Justice, NASA, and the U.S. Federal Reserve. This ...

    Asharq Al-Awsat

    أميركا تُعلن إحباط محاولة «قرصنة صينية» لمؤسسات حكومية

    The United States has announced the disruption of a Chinese hacking attempt that targeted networks belonging to the U.S. Department of Justice, NASA, and the Senate. This operation highlights ongoing cybersecurity threats and the vulnerabilities face...

    HuffPost

    U.S. Says Chinese Hackers Broke Into Justice Department, NASA, Federal Reserve, Senate And More

    The U.S. has reported that Chinese hackers successfully breached several sensitive agencies, including the Justice Department, NASA, and the Federal Reserve. This intrusion highlights ongoing cybersecurity threats posed by state-sponsored actors, par...

    HuffPost

    U.S. Says Chinese Hackers Broke Into Justice Department, NASA, Federal Reserve, Senate And More

    The U.S. Department of Justice has reported that Chinese hackers successfully infiltrated several sensitive agencies, including the Justice Department, NASA, the Federal Reserve, and the U.S. Senate. This breach underscores the ongoing threat posed b...

    Techmeme

    The US DOJ says it disrupted a Chinese hacking operation responsible for break-ins at the DOJ, NASA, the Fed, Senate, and others, seizing two platforms' domains (Reuters)

    The U.S. Department of Justice announced the disruption of a Chinese hacking operation linked to significant breaches at various federal agencies, including the DOJ, NASA, and the Federal Reserve. The operation involved the seizure of two domains ass...