US Seizes Domains of Two Hacking Platforms It Says Chinese State-Sponsored Group Used to Breach Federal Agencies
|
The Facts
- The Justice Department and FBI announced on Aug. 26 the seizure of internet domains used by two hacking platforms called QScan and QTRouter.
- The Justice Department said a Chinese state-sponsored hacking group known as QTFY created and operated the two platforms.
- Court documents link QTFY to a China-based firm, Nanjing Xinjiuwei Network Technology Company.
- An affidavit named NASA, the Federal Reserve, the Senate, the Justice Department, the Energy Department, HHS and NIH among the victims.
- The affidavit also listed four unnamed companies in the United States and South Korea as victims.
- The Justice Department said QTFY sold hacking services to paying customers including China's Ministry of State Security and the People's Liberation Army.
- Officials said the platforms infected internet-connected devices and were used to conceal the origin of the attacks.
- The affidavit says the infrastructure had been used to compromise networks since at least 2018.
- China's foreign ministry rejected the US accusations, saying they lack factual evidence; Beijing has consistently denied responsibility for hacking.
Context
What did QScan and QTRouter reportedly do?
US officials said the two platforms worked in tandem: they infected thousands of internet-connected devices and routed intrusions through them, masking where the attacks originated infobae,Al Jazeera Online. FBI Director Kash Patel described the operation as a global botnet and hacking platform, and said the FBI seized the infrastructure and shut the platforms down Zero Hedge. The Justice Department said the platforms were used to target US critical infrastructure and other sensitive networks CNBC,El Universal.
Which specific intrusions have been described so far?
According to the affidavit, hackers unsuccessfully attempted to access NASA networks in August 2019, and in September 2024 breached networks at three Department of Energy national laboratories Al Jazeera Online,NY Post. The affidavit says QTFY breached networks at NASA, NIH, the Justice Department, HHS, the Federal Reserve and the Senate over a period beginning in 2018 NY Post.
How has China responded?
Foreign ministry spokesperson Lin Jian said on Aug. 27 that Beijing firmly opposes the accusations, which he said lack factual evidence, and accused Washington of using cybersecurity as a pretext to smear China and of abusing law enforcement measures for political ends infobae. The Chinese Embassy in Washington did not immediately respond to requests for comment from reporters on the day of the announcement Aol,Independent.
Where Left and Right agree, and where they split
- Where Left and Right agree
- Seven years of access to NASA, the Fed and the Senate, sold as a service to Chinese military and intelligence buyers, is a failure that domain seizures do not undo.
- Where Left and Right split
- The left and the right split on whether this is neglect at home or aggression that cost China nothing.
- Why they won’t converge
- The divide is over remedy, not fact: one side reads a seven-year intrusion as proof of neglected domestic defenses, the other as proof that foreign buyers face no cost — and the affidavit documents both at once.
How left and right read it
The public institutions people depend on are the target here — NIH, HHS, the Energy Department, the Federal Reserve, the Senate — and an affidavit says the infrastructure used against them has been compromising networks since at least 2018. That is a defense problem seven years deep, run by a group the Justice Department says sold access to China's Ministry of State Security and the People's Liberation Army. Domain seizures are real work. But the silence from the top, on a day of steady posting, tells you where the priority isn't.
“President Trump has not commented on the DOJ's announcement, even though he has been posting on his Truth Social account all day.” — The New Republic
Sovereignty means a foreign power cannot buy its way into your government's networks as a commercial service — yet the Justice Department says QTFY, tied to a Nanjing firm, sold access to China's Ministry of State Security and the People's Liberation Army, with NASA, the Federal Reserve and the Senate among victims since at least 2018. Seizing domains is not a cost. Deterrence requires making the buyers pay.
“Chinese state-sponsored hackers infiltrated US government computer networks ranging from NASA to the US Senate before having web domains linked to their malicious cyber group shut down by the feds.” — New York Post
Espionage went retail: China's spy service and army were paying customers, buying access the way anyone buys software. Seizing the storefront leaves the buyers untouched.
The receipts — all 100 sources
Wire services (6)
Independent coverage (50)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.