Grand Pinnacle Tribune

Intelligent news, finally!
World News · 6 min read

US Disrupts China-Linked Botnet Targeting NASA And Senate

Federal agencies seize domains tied to QTFY, a Chinese state-backed hacking group accused of breaching US government and infrastructure networks using infected IoT devices and sophisticated proxy networks.

In a sweeping move against state-sponsored cyber threats, U.S. authorities have dismantled two major hacking platforms allegedly operated by a China-linked group known as QTFY, targeting some of the most sensitive government and critical infrastructure networks in America. The coordinated operation, announced by the Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) on August 27, 2026, marks one of the boldest efforts yet to disrupt the shadowy world of international cyber-espionage—and it’s raising urgent questions about the vulnerabilities lurking in everyday internet-connected devices.

According to court documents unsealed in the Southern District of California, the infrastructure seized is tied to QTFY, a state-sponsored hacking group operating out of Nanjing Xinjiuwei Network Technology Company in China. This company, investigators allege, provided hacking services to a roster of powerful clients, including China’s Ministry of State Security and the People’s Liberation Army. The DOJ has accused QTFY of orchestrating a sprawling campaign of cyberattacks that reached deep into the heart of U.S. government and industry.

Among the victims named in the investigation are heavyweights: NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. But the campaign didn’t stop at government agencies. Hospitals, health systems, telecom firms, defense contractors, power companies, and financial institutions were also in the crosshairs, according to FBI and DOJ statements cited by Cybersecurity Dive and TechRadar.

At the center of the operation were two platforms: QScan and QTRouter. QScan, as described in the DOJ’s unsealed filings, scanned the internet for vulnerable Internet of Things (IoT) devices—think routers, security cameras, and other everyday hardware. Once a device was found to be susceptible, QScan would automatically infect it with malware, enrolling it into the QTRouter network. QTRouter then combined these compromised devices with commercial proxy services and leased virtual private servers. The result? A vast, global obfuscation network that could route malicious traffic through unsuspecting systems worldwide, making it nearly impossible to trace the true origins of an attack.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel, as quoted by TechRadar. “These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down.”

The technical sophistication of the QTFY campaign was striking. The FBI and National Security Agency (NSA) reported that the group used both zero-day and N-day vulnerabilities to gain an initial foothold in victim networks—sometimes exploiting flaws that were unknown even to the product makers. Once inside, QTFY hackers would steal legitimate credentials, allowing them to maintain persistent access and move laterally within networks.

Several high-profile vulnerabilities were exploited, according to the joint advisory released by the FBI, NSA, and the Cyber National Mission Force. These included CVE-2024-24919 in Check Point Quantum Gateway, which was used to scan power and telecom firms in 2024; CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti Cloud Services Appliance, targeting Department of Energy labs and other agencies; an authentication bypass in CrushFTP (CVE-2025-31161) used against a U.S. biotech firm; and CVE-2026-1731 in BeyondTrust, which was exploited to breach a U.S. state government and a water district.

The breadth and depth of QTFY’s campaign were further detailed by researchers at Black Lotus Labs, part of Lumen Technologies. Damon Rouse, a senior information security engineer at Black Lotus Labs, described the operation as a “quartermaster model”—a seamless integration of reconnaissance, proxy orchestration, and operational routing designed to shield the true nature of the cyberattack campaign. “From what we saw, this was a classic espionage campaign focused on reconnaissance, exploitation, and information collection,” Rouse told Cybersecurity Dive. “We did not observe any information influence operations or destructive components.”

What’s perhaps most alarming is the way QTFY blurred the lines between criminal hacking groups and hostile intelligence services. As John Riggi, national advisor for cybersecurity and risk at the American Hospital Association, told the press, “This serious China-based cyber threat once again demonstrates that the line between foreign criminal hacking groups, their infrastructure and hostile intelligence services is becoming increasingly blurred.” Riggi emphasized how common internet-connected devices—often overlooked in security planning—can serve as discreet platforms for advanced cyber threat actors to mask their movements and penetrate networks.

The DOJ said the domains seized were hard-coded into the QScan and QTRouter malware, supporting essential functions like communications and authentication. By taking control of these domains, investigators effectively rendered the platforms inoperable, at least for now. But the underlying problem remains: the continued use of insecure IoT devices, proxy networks, and rented virtual servers as tools for attribution evasion.

This latest action is part of a broader pattern of U.S. technical operations aimed at disrupting Chinese cyber infrastructure. In 2025, the FBI removed PlugX surveillance malware from over 4,000 infected U.S. computers in an operation linked to the group Mustang Panda. The previous year, authorities dismantled a large IoT botnet allegedly operated by Flax Typhoon. And in 2023, the FBI disrupted Volt Typhoon infrastructure used to conceal attacks on U.S. and foreign critical infrastructure.

Alongside the disruption, the FBI and NSA released a cybersecurity advisory containing indicators of compromise associated with QTFY activity dating back to at least 2018. The advisory urges organizations to review these indicators, monitor outbound traffic for unusual proxy behavior, patch exposed devices, and restrict unnecessary internet access for IoT systems. NSA officials also recommended applying the latest firmware updates, isolating critical systems from edge devices, and auditing webpages and internet-facing applications for suspicious activity.

For many organizations, the lessons are clear but daunting. The ubiquity of internet-connected devices—often poorly secured and rarely updated—creates a vast attack surface that sophisticated actors like QTFY can exploit with alarming efficiency. As the U.S. continues to grapple with the fallout of these breaches, cybersecurity experts warn that vigilance, rapid patching, and robust network monitoring are more crucial than ever.

Attorney General Todd Blanche summed up the government’s stance, stating that the United States “will use every available tool to stop state-sponsored hackers targeting critical infrastructure.” The battle lines in cyberspace are shifting rapidly, with adversaries growing more cunning and the consequences of inaction becoming ever more severe. As the dust settles from this latest disruption, the race to secure America’s digital frontiers continues—one vulnerable device at a time.

Sources