The United States has disrupted what officials describe as a Chinese state-sponsored hacking operation that infiltrated or attempted to breach networks belonging to several high-profile U.S. government agencies, including the Justice Department, NASA, Federal Reserve and U.S. Senate.
The U.S. Department of Justice said it seized internet domains associated with two hacking platforms, QScan and QTRouter, which investigators say were used to support the campaign. The platforms allegedly helped hackers conceal their activities and gain access to targeted computer networks.
Chinese-Linked Group Accused
U.S. investigators identified the hacking operation as being linked to a group known as QTFY, allegedly operated by Nanjing Xinjiuwei Network Technology Company. According to U.S. authorities, the company had connections to China’s Ministry of State Security and the People’s Liberation Army.
The alleged campaign dates back to at least 2018 and involved thousands of compromised internet-connected devices that were used to disguise the origin of cyberattacks. The operation reportedly targeted not only government agencies but also critical infrastructure and private-sector organizations.
Other organizations identified in court documents as targets or victims include the Department of Energy, Department of Health and Human Services and National Institutes of Health, as well as companies in the United States and South Korea.
FBI Disrupts Global Botnet
FBI Director Kash Patel described the operation as a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.
The seizure of the domains is intended to prevent the operators from communicating with compromised devices and using the infrastructure to launch or conceal further attacks. U.S. officials said the disruption made important parts of the network inoperable.
The hacking campaign highlights the growing use of compromised devices and proxy infrastructure by sophisticated cyber actors. By routing malicious traffic through legitimate or compromised systems, hackers can make it significantly harder for investigators to identify the true source of an intrusion.
Beijing Denies Involvement
China has rejected U.S. accusations of state-sponsored hacking, as Beijing has routinely denied responsibility for cyberattacks attributed to Chinese actors.
The latest confrontation adds to already heightened cybersecurity tensions between Washington and Beijing, with U.S. officials repeatedly accusing Chinese-linked groups of conducting cyber espionage against government agencies, businesses and critical infrastructure.
Growing Cybersecurity Concerns
The latest operation underscores the increasingly international nature of cyber threats facing governments and critical infrastructure. Officials and cybersecurity researchers say state-linked groups are continuing to develop methods for gaining access to sensitive networks while attempting to conceal their identities.
For Washington, the disruption is both a law-enforcement action and a warning to organizations operating critical systems. The seizure of the QScan and QTRouter infrastructure demonstrates that U.S. authorities are increasingly using court orders and technical operations to disrupt foreign cyber campaigns.
However, cybersecurity experts caution that dismantling one network does not necessarily eliminate the threat. Sophisticated hacking groups can rebuild infrastructure, adopt new tools and seek alternative methods of accessing targeted systems.
The operation is therefore expected to add further pressure on the United States and China to address cybersecurity risks as broader tensions between the two countries continue to extend into technology, national security and critical infrastructure.
________________________________________________________________________________________________________________

