US seizes domains used by Chinese state-sponsored hackers who infiltrated NASA, Senate, and Federal Reserve

FBI action targets QTFY group alleged to have operated a botnet against critical infrastructure since 2018

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources3 outlets
The U.S. Department of Justice and FBI have seized three domains linked to a Chinese state-sponsored hacking group known as QTFY, which they say compromised systems at NASA, the Senate, the Federal Reserve, and multiple other federal agencies, marking a significant escalation in efforts to disrupt persistent cyber espionage operations originating from the People's Republic of China.

In a statement released Wednesday, the Justice Department said that the QTFY group — working on behalf of the PRC's Ministry of State Security — used two custom malware tools, QTRouter and QScan, to build and operate a botnet targeting U.S. government and critical infrastructure networks. QScan is described as malware that "scans and automatically infects thousands of IoT devices worldwide," with those devices then funneled into a proxy network obscuring the source of malicious traffic.

According to the FBI affidavit, the group has been active since at least 2018. The investigation began in 2019 after a system intrusion at NASA was traced to the now-patched CVE-2019-11510 vulnerability. Investigators linked the activity to two Gmail accounts and a Chinese (+86) phone number. The group allegedly rented infrastructure from hosting provider Hostwinds, leading to multiple abuse complaints, and registered the three seized domains — qtproxy.xyz, qt-proxy.org, and qt-team.com — through Namecheap, paying via PayPal between 2022 and 2024.

The affected agencies include the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, NASA, and the U.S. Senate. The DOJ stated that QTFY is employed by the Nanjing Xinjiuwei Network Technology Company, though little public information exists on that entity. All three domains now display a federal seizure notice.

While Beijing routinely denies involvement in hacking campaigns, a Wall Street Journal report from late last year revealed that Chinese officials had privately acknowledged responsibility for a series of attacks on U.S. infrastructure during a secret meeting. In 2024, it was reported that Chinese attackers had compromised wiretap systems deployed by the U.S. government in telecom networks — systems that had been in place for over 30 years.

§

Analysis

Why This Matters

  • The breaches affected multiple high-value U.S. government agencies, including the Federal Reserve, NASA, and the Senate, demonstrating persistent compromise of sensitive networks.
  • The use of IoT devices as a proxy layer makes attribution and takedown difficult; this case shows law enforcement can still disrupt command-and-control infrastructure.
  • The acknowledgment by Chinese officials of some attacks (per the WSJ) signals a potential shift in diplomatic dynamics — though Beijing still publicly denies such operations.

Background

The QTFY group's operations date back to at least 2018, when it began targeting U.S. critical infrastructure using IoT botnets. The FBI first detected the group in 2019 during an investigation into a NASA intrusion exploiting a known vulnerability in Pulse Secure VPN (CVE-2019-11510). Over the next several years, investigators traced the group's infrastructure through commercial hosting providers, domain registrars, and payment services. The three domains seized this week were registered between 2022 and 2024, suggesting the group continued to operate despite early detection. The DOJ's action follows a broader pattern: in 2024, Chinese hackers were reported to have compromised legacy U.S. government wiretap systems, and in late 2025, Chinese officials reportedly acknowledged involvement in infrastructure hacks during a closed-door meeting.

Key Perspectives

U.S. Department of Justice and FBI: The agencies assert that QTFY is a state-sponsored group working for the PRC Ministry of State Security, and that the domain seizures disrupt a years-long campaign of espionage and potential sabotage. They emphasize the botnet's use of compromised IoT devices to mask activity. People's Republic of China (official position): Beijing routinely denies allegations of state-sponsored hacking. However, the WSJ report of a private acknowledgment suggests internal recognition of these operations, complicating the official denial narrative. Critics and skeptics: Some cybersecurity experts caution that domain seizures, while disruptive, are often temporary — operators may quickly register new domains. Others note that the U.S. response focuses on infrastructure rather than individuals, potentially limiting deterrence. There are also concerns that this public attribution could escalate tensions between the U.S. and China, making cooperation on other issues more difficult.

What to Watch

  • Whether the DOJ unseals indictments against specific individuals named in the affidavit, similar to past cases against Chinese hackers.
  • How quickly QTFY or affiliated groups set up new command-and-control infrastructure and whether they retaliate by targeting additional U.S. networks.
  • China's official response — whether it publicly denies the allegations or refrains from comment, and whether the private acknowledgment reported by WSJ leads to any change in policy.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.