QTFY: China's Eight-Year Hack of US Infrastructure

NASA, the Federal Reserve, the Senate. Eight Years.
On August 26, 2026, the Justice Department and FBI announced they had seized the internet domains that powered QScan and QTRouter, two hacking platforms operated by a People's Republic of China state-sponsored group known as QTFY. The seizure made both platforms inoperable. The group had been running them since at least 2018. Eight years. Seven named federal agencies. Hundreds of additional targets across hospitals, power companies, telecommunications providers, and defense contractors. All traceable to Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services directly to China's Ministry of State Security and the People's Liberation Army.
The List of Targets
The DOJ's court action unsealed a federal affidavit in California confirming the targets by name. NASA. The Federal Reserve. The Department of Energy. The Department of Justice itself. The Department of Health and Human Services. The National Institutes of Health. The US Senate. Those are the named agencies. The broader list, described in aggregate, includes hospitals, power companies, telecommunications providers, financial institutions, and defense contractors across the United States. In September 2024 alone, QTFY hackers conducted confirmed intrusions at three Energy Department laboratories, the NIH, an HHS agency, and an unnamed US security device manufacturer. The 2024 entries are a sample. The access ran from 2018 onward.
Named federal agencies
NASA, Federal Reserve, DOJ, DOE, NIH, HHS, US Senate
Front company
Nanjing Xinjiuwei Network Technology Co.
Clients
China Ministry of State Security, People's Liberation Army
Active period
2018 to August 26, 2026
Court action reference
DOJ press release 26-972
How QScan and QTRouter Worked
QTFY sold two tools. QScan automatically scanned the internet for vulnerable devices, infected them, and harvested access credentials. It targeted Internet of Things devices globally: home routers, industrial sensors, anything with an open port and outdated firmware, turning them into unwitting relay stations. QTRouter then used those infected devices, layered with commercial proxy services and virtual private servers, to obscure the true origin of attacks. Every connection to a target appeared to come from an anonymous router in an American suburb rather than a server farm in Nanjing. Standard network defenses log source IPs. QTFY's infrastructure ensured those IPs were real US home broadband addresses. Investigators only traced the chain back by following how QScan communicated with hard-coded command-and-control domains. Those are the domains the FBI seized on August 26. Without them, both QScan and QTRouter lost the ability to receive instructions or authenticate. They went dark.
QTFY Is the Fourth, Not the First
The QTFY seizure sits inside a pattern that started at least three years earlier, and has grown larger each time. In 2023, the FBI disrupted a botnet used by Volt Typhoon to conceal attacks on US critical infrastructure. In 2024, it disabled a botnet of hundreds of thousands of infected IoT devices run by Flax Typhoon. In January 2025, it removed PlugX surveillance malware from more than 4,200 US computers placed there by Mustang Panda, a PRC-sponsored group. In August 2026: QTFY, eight years of access sold commercially to the PLA and the MSS. The escalation in scale is the story. Volt Typhoon targeted routers. Flax Typhoon ran a botnet. Mustang Panda had PlugX on 4,200 machines. QTFY had the Federal Reserve.
"It's not as if by us doing this, that they're going to walk away and not try again. They're going to reload and try and come at us again, and so this is a fight that we're going to continue to have to have.
"Attorney General Todd Blanche · DOJ · August 26 2026
The National Emergency and What It Does Not Settle
The White House, responding to the broader pattern of PRC cyber operations against power company networks, declared a national emergency for the US power grid on August 27, directing agencies to remove components made by foreign adversaries. The DOJ's QTFY affidavit confirmed that power companies were among the targets. It stopped short of establishing that operational systems, the ones that actually control electricity flow, had been compromised. The gap between "access to the power company's network" and "access to the systems controlling the grid" matters. The affidavit does not close it. QTFY's tools are now inoperable. The group is not. The DOJ has issued technical advisories to help organisations determine whether their networks show signs of QTFY activity. This is the fourth major PRC cyber infrastructure takedown in four years. The fifth is presumably already under construction.



