FBI Seizes Chinese Hacking Tools Used to Breach NASA, Senate, and Energy Department

Court-ordered seizure disrupts botnet and obfuscation network operated by Nanjing Xinjiuwei-linked group QTFY

edit
By LineZotpaper
Published
Read Time2 min
The FBI announced Wednesday it had seized two hacking platforms and disrupted a botnet used by a Chinese government-backed group to infiltrate networks at NASA, the US Senate, the Department of Energy, and other critical agencies, according to court documents unsealed this week.

The U.S. Justice Department said the FBI executed seizure warrants on three domains — qtproxy.xyz, qt-proxy.org, and qt-team.com — that were hardcoded into two malware platforms: QScan, a vulnerability scanning and exploitation tool, and QTRouter, an obfuscation network that allowed attackers to hide the origin of their intrusions.

Together, the platforms created a botnet of compromised IoT devices, commercial proxy services, and leased virtual private servers used to attack a wide range of victims. Court documents allege the tools were operated by a Chinese government-backed group known as QTFY, which the FBI says works for a private company called Nanjing Xinjiuwei.

“Payments from the PRC’s Ministry of State Security (MSS) to Nanjing Xinjiuwei … indicate that the company conducts malicious cyber activities on behalf of the PRC Government,” the court documents state. The documents also note that QTFY actors include former members of the People’s Liberation Army.

The hacking campaigns date back to at least 2018. In 2019, QTFY attempted to compromise NASA by exploiting CVE-2019-11510, a critical vulnerability in Ivanti’s Pulse Secure VPN. The same bug was used as a zero-day against dozens of defense and financial organizations, as previously reported. During the COVID-19 pandemic in 2020, the group targeted a medical center in Ohio. Victims also include financial groups in Michigan and South Korea, and a Missouri insurance agency.

More recently, in 2024, QTFY breached three DOE National Laboratories, the National Institutes of Health, and a U.S. security device manufacturer using a zero-day attack against Ivanti Cloud Services Appliance.

The FBI’s operation made both QScan and QTRouter inoperable by seizing the command-and-control domains. The disruption follows a pattern of U.S. court-ordered seizures aimed at Chinese hacking infrastructure, including the 2025 removal of PlugX surveillance malware from thousands of devices.

China has consistently denied state-sponsored hacking allegations. As of press time, the Chinese embassy in Washington had not responded to requests for comment. The FBI declined to provide details on the total number of compromised computers or whether QTFY is linked to other known Chinese cyber groups such as those named after weather phenomena (e.g., Volt Typhoon).

§

Analysis

Why This Matters

  • The breach of critical U.S. government agencies — including NASA, the Senate, and DOE — demonstrates that Chinese state-sponsored hackers have achieved persistent access to sensitive networks over many years.
  • The disruption of the QTRouter obfuscation network may temporarily hinder operations, but similar infrastructure is likely already being rebuilt, underscoring the difficulty of defending against resourceful state actors.
  • The use of IoT device botnets as proxy networks highlights a growing threat to consumer and industrial devices, which are often poorly secured and easily co-opted.

Background

China has long been accused of conducting cyber espionage against the United States and its allies. The QTFY group, linked to Nanjing Xinjiuwei, appears to be one of several private contractors that the Chinese government uses to conduct offensive operations. The group has exploited known vulnerabilities in VPN products from Ivanti and Citrix, as well as zero-days. Previous U.S. actions include the 2025 FBI takedown of PlugX malware and multiple indictments against Chinese military hackers. The latest seizure adds to a pattern of legal and technical disruption, though critics argue such actions are a game of whac-a-mole.

Key Perspectives

U.S. government (FBI/DOJ): The seizure is a necessary law enforcement action to protect national security. The evidence in court documents provides a detailed picture of state sponsorship, including financial flows from the MSS to Nanjing Xinjiuwei. Chinese government: Beijing routinely denies state-sponsored hacking and may characterize the U.S. actions as baseless accusations or as part of a broader “cyber cold war” narrative. Cybersecurity experts: While the takedown is operationally significant, experts caution that the infrastructure will likely be re-established quickly. They also note that the reliance on private contractors complicates attribution and response.

What to Watch

  • Whether the U.S. government issues additional indictments or sanctions against individuals named in the court documents.
  • The timing and nature of any diplomatic friction between Washington and Beijing over this incident, especially in ongoing cyber dialogues.
  • Signs of new or modified versions of QScan and QTRouter emerging in the wild, indicating that the group has adapted its tools.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.