US Seizes Domains Tied to Chinese-Linked Hacking Platforms
US authorities announced Wednesday the seizure of two internet domains used by hacking platforms that allegedly targeted sensitive US government networks, including those of the Federal Reserve, the US Senate, NASA, and the Department of Justice. The operation, detailed by the Justice Department and the FBI, involved platforms known as QScan and QTRouter, which court documents say were created and operated by a Chinese state-sponsored group named QTFY.
The seized domains were hard-coded into both QScan and QTRouter malware, and the seizures made the platforms inoperable, the Justice Department said. According to an affidavit, the infrastructure had been used to compromise critical infrastructure and other sensitive networks in the US and elsewhere since at least 2018.
QTFY was employed by Nanjing Xinjiuwei Network Technology Co., a China-based company, and its paying customers included China's Ministry of State Security and the People's Liberation Army, the Justice Department stated. The platforms were reportedly used to break into internet-connected devices and hide the source of attacks.
Details of the Operation and Targets
The Justice Department's announcement said QScan was used to find and infect thousands of internet-connected devices, including routers and other network equipment, which were then incorporated into a network via QTRouter. Court filings also listed other targeted networks, including those operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
Initially, the Justice Department said several federal agencies were victims of computer intrusions, naming the Federal Reserve, the US Senate, NASA, the Department of Justice, the Energy Department, the Health and Human Services Department, and the National Institutes of Health. Court documents indicated that hackers had unsuccessfully attempted to access NASA networks in August 2019 and, in September 2024, successfully breached networks at three Department of Energy laboratories, NIH, HHS, and a US security-device manufacturer.
However, in a later edited statement, the Justice Department described the US Senate, the Federal Reserve, NASA, and others as "among the targets of QTFY," rather than victims. A note at the bottom of the edited statement said, "Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures." Reuters reported that it could not immediately establish which specific agencies the government now believed had been targeted and which had been breached, and that messages seeking clarification from the Justice Department, the FBI, and CISA were not immediately returned.
Official Statements and Responses
US Attorney General Todd Blanche, in a statement Wednesday, said, "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise." He also said, "Federal law enforcement investigated and disabled the PRC's malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China."
The Chinese embassy in Washington responded, stating that the Chinese government opposes and combats all forms of cyberattacks. "We urge the US side to stop using cybersecurity issues to smear or discredit China," a spokesman said, according to the South China Morning Post.
Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to requests for comment by the Reuters news agency, as reported by Al Jazeera.
The operation is part of a broader series of court-authorized actions targeting what Attorney General Blanche described as "indiscriminate hacking activities" sponsored by China. The FBI's Cyber Division, federal prosecutors in California, and the San Diego field office led the investigation, according to Al Jazeera.
Perspectives
US Justice Department
The Justice Department asserts that Chinese state-sponsored hackers, operating via QTFY and Nanjing Xinjiuwei, targeted US critical infrastructure and federal agencies, and that the domain seizures disabled the malware.
Chinese Embassy in Washington
The Chinese embassy denies state involvement in cyberattacks, stating that China opposes and combats all forms of cyberattacks and urging the US to stop using cybersecurity issues to smear or discredit China.