FBI Seizes Chinese Hacker Platforms That Targeted NASA And The Senate
by
Aaron Leong
—
Thursday, August 27, 2026, 10:24 AM EDT
China-backed cyberattack infrastructure has infiltrated major US government agencies - Image: Kevin Horvat via Unsplash
Federal law enforcement has dismantled a major Chinese state-sponsored cyber-espionage apparatus that targeted critical infrastructure and key government agencies across the United States for nearly eight years. It also makes us wonder again how these operations were not caught any earlier.
This week, the U.S. Justice Department and the FBI unsealed court orders authorizing the seizure of domains hard-coded into two sophisticated hacking tools: QScan and QTRouter. Developed and operated by a China-based threat group known as QTFY (working under the commercial front of Nanjing Xinjiuwei Network Technology Company) the platforms were sold as paid hacking services to clients including China’s Ministry of State Security and the People’s Liberation Army.
The technical aspect of the operation relied on a dual-stage approach to exploit IoT devices globally. First, the QScan tool systematically scanned the internet to discover vulnerable smart devices, such as security cameras and commercial routers, and automatically infected them. These compromised endpoints were then funneled into QTRouter, creating a wide, geographically distributed proxy network. By routing malicious traffic through infected hardware located near target systems, the attackers successfully obfuscated the Chinese origin of their intrusions, making nefarious activities appear as innocent local network traffic.
Adding salt to the wound, the unsealed affidavits detail an expansive trail of targets dating as far back as 2018, with high-profile institutions like NASA, the U.S. Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, and the Department of Justice (the irony) being subjected to infiltration and reconnaissance. Private sector targets included critical power grids, defense contractors, telecommunications providers, and major hospital systems. The FBI’s investigation logged historical attacks ranging from a 2019 attempt against NASA’s VPN infrastructure to low-level vulnerability scans targeting the U.S. Senate and state election systems.
Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.
These tools were used by PRC cyber actors to hide the origin of their attacks.
— FBI Director Kash Patel (@FBIDirectorKash) August 26, 2026
Because essential operational assets like authentication and command-and-control functions were directly linked to the seized web domains, taking them offline effectively rendered both QScan and QTRouter inoperable worldwide. In a statement on X, FBI Director Kash Patel highlighted the strike, noting that law enforcement had successfully disrupted a massive global botnet and state-sponsored hacking platform used to undermine American critical infrastructure.
Simultaneously, the FBI, NSA, and U.S. Cyber Command issued a joint cybersecurity advisory warning commercial network operators and international allies about QTFY’s lingering tradecraft, urging them to continuously patch edge devices, implement strict zero-trust network access, and monitor for unauthorized proxy traffic to prevent future similar intrusions.