
WASHINGTON, D.C., United States | August 27, 2026 —
China-linked hackers US cyberattack allegations have escalated after the U.S. Justice Department and FBI announced the seizure of two hacking platforms allegedly used by a China-linked group to target some of America’s most sensitive government and critical-infrastructure networks.
The U.S. says the group, known as QTFY, used two complementary systems called QScan and QTRouter to scan vulnerable devices, compromise internet-connected equipment and conceal the true origin of malicious traffic.
Among the organizations identified by the Justice Department as victims of QTFY intrusion activity are:
- NASA
- Federal Reserve
- U.S. Department of Justice
- U.S. Department of Energy
- Department of Health and Human Services
- National Institutes of Health
- U.S. Senate
Private-sector organizations and foreign networks were also targeted.
However, the available U.S. documents do not mean every institution listed suffered the same level of compromise, nor do they establish that every attempted intrusion succeeded.
China has rejected the broader accusations of state-sponsored hacking and has repeatedly criticized Washington for politicizing cybersecurity disputes.
What Are QScan and QTRouter?
The alleged cyber campaign relied on two interconnected systems.
QScan was designed to scan large numbers of internet-connected devices and identify vulnerabilities.
According to U.S. authorities, it could automatically exploit vulnerable Internet of Things devices, including routers and similar hardware.
Once compromised, those devices could become part of a larger network.
That larger infrastructure was known as QTRouter.
QTRouter used compromised IoT devices, commercial proxy systems and rented virtual private servers to route malicious traffic.
The objective was to make cyber activity appear as though it originated somewhere other than China.
In practical terms, attackers could route traffic through compromised computers and devices around the world before reaching their intended target.
That makes tracing the true source of an intrusion much more difficult.
Why Compromised Routers Matter
A hacked router can be particularly useful to a sophisticated cyber actor.
Instead of attacking a target directly from infrastructure that might immediately reveal its origin, attackers can use an innocent third-party device as an intermediary.
The target may then see traffic apparently arriving from a normal residential or commercial connection.
This technique is known as an obfuscation network.
NSA says QTFY built such infrastructure using compromised IoT devices and other network nodes.
That approach can help attackers:
- Hide their true location
- Blend malicious traffic with normal internet activity
- Avoid some security filters
- Conduct reconnaissance
- Exploit exposed systems
- Maintain access to compromised networks
The NSA says QTFY has been operating since at least 2018.
Who Does the US Say Operated the Platforms?
The Justice Department links QTFY to Nanjing Xinjiuwei Network Technology Company, a China-based technology company.
According to U.S. court documents, QTFY allegedly provided hacking services to paying customers, including entities connected to China’s Ministry of State Security and People’s Liberation Army.
These are U.S. government allegations.
The case should therefore not be presented as a judicial finding that China itself has been convicted of conducting the campaign.
The investigation remains part of a broader U.S. effort to disrupt infrastructure allegedly used by state-linked cyber actors.
How Did the US Shut the Hacking Platforms Down?
The Justice Department obtained court authorization to seize internet domains used by QScan and QTRouter.
This was particularly effective because the seized domains were reportedly hard-coded into the malware.
The platforms relied on those domains for critical functions such as communication and authentication.
Once U.S. authorities took control of them, the Justice Department says both QScan and QTRouter became inoperable.
That means the operation did not simply block a website.
It disrupted infrastructure the malware itself needed to function.
NASA, Federal Reserve and Senate: What Was Actually Targeted?
The list of victims makes the case unusually significant.
NASA controls sensitive scientific, aerospace and space-related systems.
The Federal Reserve sits at the center of the U.S. financial system.
The U.S. Senate handles sensitive legislative and national-security information.
The Department of Energy oversees critical energy and nuclear-related infrastructure.
The Department of Justice and other agencies also hold large amounts of sensitive data.
That does not mean the attackers obtained every sensitive file or controlled these institutions.
The more accurate conclusion is that networks belonging to extremely high-value American institutions were among those targeted or affected by the alleged intrusion activity.
That distinction matters when reporting cybersecurity incidents.
QTFY Also Targeted Critical Infrastructure
The campaign was broader than federal agencies.
The NSA advisory says QTFY targeted sectors including:
- Defense industrial base
- Telecommunications
- Local government
- Higher education
- Critical infrastructure
The group allegedly exploited both zero-day vulnerabilities and already-known vulnerabilities that organizations had failed to patch.
A zero-day vulnerability is a software weakness that may be exploited before a vendor or users have had enough time to deploy a fix.
Previously disclosed vulnerabilities can be just as dangerous when organizations leave devices unpatched.
Why IoT Devices Are Becoming a Cybersecurity Weak Point
Internet-connected devices can create hidden weaknesses inside otherwise sophisticated networks.
Examples include:
- Routers
- Cameras
- Network appliances
- Smart sensors
- Gateways
- Industrial devices
These products may remain online for years.
Some receive infrequent security updates.
Others retain default passwords or outdated firmware.
Once attackers compromise enough devices, they can build a botnet or proxy network that becomes infrastructure for future attacks.
This is one reason U.S. cybersecurity agencies increasingly urge organizations to treat edge devices and routers as part of their core security perimeter.
NSA Issues Warning and Defensive Guidance
Alongside the Justice Department action, the NSA, FBI and Cyber National Mission Force released a joint cybersecurity advisory.
The agencies recommend several measures.
Organizations should:
Install current software and firmware updates.
Unpatched internet-facing devices are often attractive entry points.
Audit internet-facing applications and websites.
Organizations should minimize the amount of operational information unintentionally exposed online.
Separate critical systems from edge devices.
Network segmentation can prevent compromise of one device from becoming compromise of an entire environment.
Search for indicators of compromise.
Security teams should review the technical indicators provided in the advisory to determine whether QTFY infrastructure has interacted with their systems.
Official NSA advisory:
This Is Not the First US Operation Against China-Linked Cyber Infrastructure
The August action fits into a broader U.S. campaign against cyber infrastructure attributed to China-linked groups.
In previous operations, American authorities have disrupted botnets and removed malware linked to groups including:
- Mustang Panda
- Flax Typhoon
- Volt Typhoon
The Justice Department says the latest seizure continues that strategy: rather than waiting for individual attacks, law-enforcement agencies are attempting to dismantle the technical infrastructure used to support them.
Why the Federal Reserve Angle Matters
The Federal Reserve is especially sensitive because cybersecurity involving financial infrastructure can have consequences beyond a single agency.
A serious compromise involving financial systems could potentially affect:
- Payment infrastructure
- Sensitive economic information
- Financial-market confidence
- Banking-sector operations
- Government communications
Again, U.S. authorities have not said QTFY gained control over the Federal Reserve or disrupted U.S. monetary policy.
The importance lies in the fact that such a high-value financial institution was reportedly within the campaign’s target set.
Cybersecurity Is Becoming Part of US-China Strategic Competition
Cybersecurity has joined semiconductors, artificial intelligence, telecommunications and supply chains as one of the central areas of strategic competition between Washington and Beijing.
Both countries increasingly view digital infrastructure as a national-security asset.
The latest operation also arrives as the United States places greater emphasis on protecting strategic technology and infrastructure supply chains.
Also Read – : India, US Deepen Semiconductor and AI Partnership in Washington Talks on Supply Chains and Critical Minerals
China Rejects US Cyber Allegations
China has consistently denied U.S. accusations that it sponsors malicious cyber campaigns.
Following the latest U.S. announcement, China’s diplomatic representatives rejected the accusations and argued that Washington should avoid politicizing cybersecurity.
The competing claims illustrate one of the difficulties of state-linked cyber incidents.
Unlike a conventional military attack, malicious digital traffic can pass through servers and compromised devices across several countries.
That makes attribution technically and politically contentious.
The United States says its conclusions are supported by court-authorized investigations, malware analysis and intelligence gathered over several years.
Did China Hack NASA and the Federal Reserve?
The safest answer is more precise than many headlines suggest.
The U.S. Justice Department says a China-linked hacking group conducted intrusion activity targeting networks including NASA, the Federal Reserve and the U.S. Senate.
That is not the same as saying every agency was fully breached or that all of its systems were compromised.
Cyber campaigns often include:
- Reconnaissance
- Vulnerability scanning
- Attempted intrusion
- Successful compromise of individual systems
- Credential theft
- Persistence inside networks
The extent of access can vary greatly from one victim to another.
What Happens Next?
The seized QScan and QTRouter infrastructure is now disabled, according to U.S. authorities.
But that does not mean QTFY or similar groups have disappeared.
Cyber actors can rebuild infrastructure, develop new malware and shift to new compromised devices.
For governments and companies, the longer-term lesson is therefore larger than a single takedown.
Modern cyber espionage increasingly depends on ordinary internet-connected devices that can quietly become part of an attack network.
And the latest U.S. case demonstrates just how valuable those networks can become when the eventual targets include NASA, central banking institutions, lawmakers and critical infrastructure.
The cyber contest between major powers is therefore no longer taking place only inside government intelligence systems.
It is increasingly running through routers, servers and IoT devices connected to the ordinary internet.










