Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Disrupts China-Linked Hacking Tools Targeting US Agencies

Network device on a rack in a dimly lit operations center.

"QScan carried code for more than 200 different attacks and on one day in 2024 processed more than 2 million scanning or exploitation tasks," a federal affidavit says — a scale that turns routine internet reconnaissance into an industrialized threat.

QScan and QTRouter: automated scouting and deliberate concealment

Prosecutors describe two complementary tools at the heart of the operation. QScan scanned the internet for vulnerable systems and attempted exploitation, carrying code for more than 200 different attacks and operating at very high throughput. QTRouter was the concealment layer: it routed the hackers’ traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers so activity would appear to originate from places other than China.

According to the FBI affidavit, the system mixed malicious traffic with that of ordinary internet users, complicating detection and blocking. Lumen Technologies, which tracked the same infrastructure for roughly a year, called the operator an "infrastructure quartermaster" — a ready-made service that other China-linked hackers could use to find targets and hide their tracks. Lumen observed that networks first probed by QScan later appeared to communicate through the concealed network, suggesting operations sometimes moved from reconnaissance toward attempted intrusion.

Targets: U.S. agencies, research labs and critical services

Court records and the affidavit tie the tools and infrastructure to attempted targeting of a long list of U.S. agencies and critical sectors. Named victims include NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services. The filings also cite hospitals, telecommunications providers, power companies, banks and defense contractors among the targets.

The record does not claim every attempt succeeded: a 2019 effort against NASA failed because the agency had already remediated the security flaw the hackers tried to exploit. Investigators also tied the group’s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea, and an insurance organization in Missouri.

Attribution: QTFY and a private company with state ties

The Justice Department attributed QScan and QTRouter to a hacking group identified as QTFY. Court records say QTFY operates through Nanjing Xinjiuwei Network Technology Company, described as a private Chinese firm that sold hacking services to China's main civilian intelligence agency and to its military. Investigators flagged the case as further evidence that Chinese intelligence and military agencies have relied heavily on private companies for cyber operations and services.

Prosecutors said QTFY could rapidly exploit newly disclosed vulnerabilities at scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after public disclosure, stealing server settings and user account information from more than 300 U.S. organizations, per the court documents. Several months later, the filing says, the group used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.

FBI domain seizures and precedent operations

On Wednesday the FBI seized three internet domains prosecutors say QTFY used to target U.S. agencies, critical infrastructure and other networks. FBI Director Kash Patel was quoted directly: “These tools were used by PRC cyber actors to hide the origin of their attacks.”

The announcement follows several prior U.S. operations that disrupted China-linked hacking infrastructure. Last year the bureau removed PlugX surveillance malware from more than 4,200 U.S. computers infected by another state-backed hacking group. Federal authorities have also dismantled a network of compromised routers, cameras and devices associated with Flax Typhoon and disrupted a network Volt Typhoon used to hide attacks against U.S. critical infrastructure.

What this means for network defenders, policymakers, and affected agencies

  • Network defenders and security teams: Expect scrutiny of edge devices and proxy usage. The tools described combined mass-scale scanning with traffic-mixing through hijacked routers and commercial proxies, which makes identifying malicious flows harder. Observables tied to QScan and QTRouter — including domains seized by the FBI — are now actionable intelligence to block and investigate.
  • Policymakers and regulators: The case underscores how private-sector providers can be repurposed by state-linked actors. Regulators concerned with supply chain and vendor risk will note the court record linking a private firm to state intelligence and military customers.
  • Affected agencies and research institutions: The filings document a pattern of rapid exploitation of newly disclosed and zero-day flaws, including the May 2024 Check Point incident and the Ivanti-related intrusions. Patch management, incident response readiness, and aggressive logging around remote access and security appliance configurations are immediate operational priorities.

The FBI’s action disables three domains and exposes a multi-layered service that converted mass scanning into targeted attacks. The record shows a mix of blunt-scale automation and careful concealment — an operational pattern that investigators say aided rapid exploitation of newly disclosed vulnerabilities and the hiding of origin. The seizure removes a toolset from current use, but the affidavit itself documents methods and tradecraft others could reuse, leaving defenders and policymakers to weigh how to harden points of mass exposure and to monitor for similar infrastructure in the weeks and months ahead.

Source: Defense One — FBI disables China-linked hacking tools used against US agencies