Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Disrupts Chinese Hacking Tools Targeting US Critical Networks

Rows of computer servers and networking equipment in a bright, institutional server room with screens displaying data and a…

“Payments from the PRC's Ministry of State Security (MSS) to Nanjing Xinjiuwei, for example, indicate that the company conducts malicious cyber activities on behalf of the PRC Government,” court documents say.

What the FBI disrupted and why it matters

The FBI said on Wednesday it disrupted a botnet and seized two hacking platforms that a People’s Republic (PRC) of China-backed group called QTFY used to attack a string of high-value US targets. The seized tools are named in court filings as QScan — a vulnerability scanning and exploitation malware — and QTRouter — an obfuscation network. The Justice Department said court-authorized seizures of three domains hardcoded into both tools — qtproxy.xyz, qt-proxy.org, and qt-team.com — rendered the services inoperable.

How QScan and QTRouter worked, according to court filings

Court documents describe QScan as a scanner that automatically finds and infects thousands of internet-of-things (IoT) devices worldwide and adds them to a QTRouter network controlled by QTFY. That QTRouter botnet — made up of compromised IoT devices, commercial proxy-service devices, and leased virtual private servers — functioned as an obfuscation layer, making intrusion traffic appear to originate from local computers and hiding the true source of operations. The domains seized by the FBI were hardcoded into both QScan and QTRouter, tying the infrastructure together in the agency’s view.

Targets and timeline: CVE exploits and known intrusions since 2018

The tools have been in use since at least 2018 and as recently as this year, when court documents say QTFY infrastructure compromised the US Senate. The FBI investigated an attempted intrusion at NASA in August 2019 that tried to exploit CVE-2019-11510, a critical vulnerability in Ivanti’s Pulse Secure VPN that could expose usernames and passwords; Ivanti patched that flaw in April 2019. Court filings also link QTFY to exploitation of CVE-2019-11510 in 2020 against a medical center in Ohio, and to an unrelated exploitation of CVE-2019-19781 — a critical Citrix VPN flaw — in an attack on a Missouri insurance agency in 2019. In 2024, QTFY actors were also tied to break-ins at three Department of Energy National Laboratories, the National Institutes of Health, and a US security device manufacturer via a zero-day against Ivanti Cloud Services Appliance, the filings say.

Nanjing Xinjiuwei, QTFY, and alleged PRC links

The FBI’s filings attribute the creation and operation of QScan, QTRouter and related botnets to QTFY, and further link QTFY’s operators to a private PRC company named Nanjing Xinjiuwei. Court documents state that QTFY actors “include former members of the PRC's People's Liberation Army (PLA), and they use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations,” and that payments from the PRC’s Ministry of State Security to Nanjing Xinjiuwei indicate the company “conducts malicious cyber activities on behalf of the PRC Government.”

What this means for NASA, DOE National Laboratories, and the US Senate

  • NASA: An attempted intrusion in August 2019 leveraged CVE-2019-11510, illustrating how unpatched or previously exploited VPN vulnerabilities can be reused by persistent operators; NASA was among the named victims in court filings.
  • DOE National Laboratories: The filings say three DOE National Laboratories were compromised in 2024 via a zero-day against Ivanti Cloud Services Appliance, highlighting continued risk to research and critical infrastructure networks.
  • US Senate: The court record asserts QTFY infrastructure compromised the US Senate as recently as this year, signaling the operational reach of the botnet and the obfuscation value QTRouter provided to its operators.

The disruption is the latest in a series of court-ordered takedowns the FBI and allied entities have pursued against PRC-linked operations: the bureau removed PlugX surveillance malware from more than 4,000 US computers in 2025, courts ordered disruption of other botnets operated by PRC-sponsored crews in 2023 and 2024, and private researchers later reported resurgences or clusters tied to some groups. Lumen’s Black Lotus Labs, for example, reported in June a “significant resurgence” of a botnet cluster linked to Volt Typhoon that surged to about 1,500 compromised routers and IoT devices.

The Justice Department’s seizure action and the FBI’s disruption leave unanswered operational questions the bureau did not address to The Register’s inquiries, including how many computers QTFY compromised in total and whether this crew has connections with named “Typhoon” groups, the reporting says. The court documents, the domains seized, and the CVEs cited together form the public evidentiary thread the government has used to attribute the platforms, but the scope and full operational history remain framed by the filings and the domains the court authorized to be removed from service.

Original story