US shuts down China-linked hacking tools accused of targeting NASA, federal agencies

 

The Justice Department and FBI said Wednesday they shut down online systems allegedly used by Chinese government-backed hackers to hide cyberattacks against U.S. critical infrastructure and government networks.

Dig deeper:

The systems, known as QScan and QTRouter, were used to infect internet-connected devices around the world and then route hacking activity through them, according to court documents. That made attacks appear to come from computers outside China instead of from the people responsible.

Officials said the hacking group, known as QTFY, was connected to a China-based company and offered hacking services to customers that included China’s Ministry of State Security and the People’s Liberation Army.

RELATED: See list: Facebook and Instagram’s new limits on kids under settlement: Daily caps, no nights, forced pauses

The group allegedly targeted several major U.S. agencies and institutions, including NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health and the U.S. Senate.

Loading PDF

What they're saying:

"State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise," Attorney General Todd Blanche said. "Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China."

According to court documents, QScan searched for vulnerable devices connected to the internet, including so-called "smart" devices, and infected them with malware. Those devices were then added to a larger network called QTRouter.

The network was used to disguise the source of hacking attempts, officials said. In some cases, the attacks could appear to be coming from computers located near the target rather than from China.

RELATED: Meta agrees to settle social media addiction case for up to $16.8B

"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," FBI Director Kash Patel said. "These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down."

The FBI and Justice Department seized web domains that the malware needed to communicate and operate. Officials said that action made QScan and QTRouter unusable.

Big picture view:

The operation follows other recent FBI actions against cyber tools tied to China, including the removal of malware from thousands of U.S. computers in 2025 and the disruption of botnets in 2023 and 2024.

The FBI and National Security Agency also released a public alert with technical information that could help organizations identify QTFY-related cyber activity.

The Source: Information in this story came from the Justice Department and FBI, which announced the court-authorized seizure of domains tied to the QScan and QTRouter hacking platforms. This story ws reported from Los Angeles. 

Technology