DOJ seizes domains used by Chinese hackers to breach NASA, Federal Reserve
The Justice Department and FBI announced the court-authorized seizure of internet domains used to operate two Chinese state-sponsored hacking platforms that breached NASA, the Federal Reserve, the U.S. Senate, and several other federal agencies, the department said on Wednesday.
Court documents unsealed in the Southern District of California identify QTFY as the group behind both platforms, with the group operating under the umbrella of Nanjing Xinjiuwei Network Technology Company, a firm headquartered in China. QTFY’s paying customers include China’s Ministry of State Security and the People’s Liberation Army, the Justice Department said.
Other federal agencies listed as victims of QTFY computer intrusion include the Departments of Energy, Justice, and Health and Human Services, as well as the National Institutes of Health. Court documents also identify hospitals, telecommunications providers, power companies, financial institutions, and defense contractors among the targets, according to CNBC.
Advertisement
Advertisement
QScan functioned as a scanning and exploitation platform that infected thousands of internet-of-things devices worldwide, adding them to the QTRouter network. QTRouter then served as an obfuscation network, routing malicious traffic through compromised devices to conceal the China origin of the intrusions, the Justice Department said. Since both platforms relied on those domains for core functions such as authentication and communications, taking them down left QScan and QTRouter unable to operate.
According to Bleeping Computer, the three domains — qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com — have been taken over and replaced with a law enforcement notice.
Attorney General Todd Blanche issued a statement declaring, “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
FBI Director Kash Patel said the platforms were used by Chinese state-sponsored actors to hide the origin of their attacks, and credited FBI San Diego, the FBI Cyber Division, and Justice Department partners with the seizure.
Advertisement
Advertisement
Wednesday’s action is part of a broader pattern of U.S. operations against Chinese hacking infrastructure. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the PRC-sponsored group Mustang Panda. In 2024, the FBI disabled a botnet of hundreds of thousands of infected devices that the PRC-sponsored group Flax Typhoon had been providing to Chinese government customers. In 2023, the FBI disrupted a separate botnet used by Volt Typhoon to conceal attacks on U.S. and foreign critical infrastructure, the Justice Department said.