FBI seizes hacking platforms it says China used against NASA, Senate

The FBI announced on Wednesday that it disrupted a botnet and seized two hacking platforms, QScan and QTRouter, that a China-backed group the Bureau calls QTFY used against NASA, the US Senate, the Department of Energy and other US networks. A federal court granted seizure warrants on Monday for three domains hardcoded into both tools: qtproxy.xyz, qt-proxy.org and qt-team.com. Seizing the domains made both hacking services inoperable, the Justice Department said. QScan is a vulnerability scanning and exploitation tool that infects IoT devices worldwide; the infected devices, plus commercial proxy servers and leased VPS machines, feed QTRouter, an obfuscation network that lets QTFY and other paying customers hide the true origin of their intrusions behind local-looking traffic.
The FBI says QTFY's hackers work for a private PRC company called Nanjing Xinjiuwei. Court documents quoted by the Bureau state that payments from China's Ministry of State Security to Nanjing Xinjiuwei indicate the company conducts malicious cyber activity on the PRC government's behalf, and that QTFY includes former People's Liberation Army members who use their PLA relationships to win contracts and subcontracts for offensive cyber operations.
Court documents say the hacking services and malware have been in use since at least 2018, with QTFY infrastructure compromising the US Senate as recently as this year. Beyond NASA and the Senate, victims named by the FBI include the Department of Energy, the Federal Reserve, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health. The FBI investigated an attempted intrusion at NASA in August 2019 that tried to exploit CVE-2019-11510, a critical flaw in Ivanti's Pulse Secure VPN patched that same April, which let attackers steal legitimate usernames and passwords. China used the same bug as a zero-day against dozens of defense contractors, government agencies and financial firms in the US and abroad. QTFY exploited it again in 2020 to attack a medical center in Ohio, and separately hit unnamed financial groups in Michigan and South Korea plus a Missouri insurance agency, the last via a different flaw, CVE-2019-19781, in Citrix VPN products. In 2024, QTFY broke into three DOE National Laboratories, NIH and a US security device manufacturer, which court documents say were victims of a zero-day attack against Ivanti's Cloud Services Appliance. The FBI would not tell The Register how many computers QTFY compromised in total, or whether the group has ties to any of China's other named "Typhoon" hacking crews.
The seizure is the latest in a run of US actions against Chinese state-linked hacking infrastructure. In 2025 the FBI removed PlugX surveillance malware from more than 4,000 US computers infected by the PRC-sponsored group Mustang Panda. In 2024, China's Flax Typhoon burned down its own IoT botnet of hundreds of thousands of devices once confronted by federal authorities, and in late 2023 the FBI disrupted a Volt Typhoon botnet that had targeted US and foreign critical infrastructure. That fight is not over: in June, Lumen's Black Lotus Labs reported a significant resurgence of a Volt Typhoon-linked botnet, with the compromised cluster growing to 1,500 routers and IoT devices.
Key facts
- The FBI seized two Chinese-linked hacking platforms, QScan and QTRouter, after a federal court granted seizure warrants on Monday for three domains hardcoded into both tools: qtproxy.xyz, qt-proxy.org and qt-team.com.
- The FBI attributes the platforms to a PRC-backed group it calls QTFY, whose hackers it says work for a private company, Nanjing Xinjiuwei, and includes former PLA members; the tools have been in use since at least 2018.
- Named victims include NASA, the US Senate, the Department of Energy, the Federal Reserve, the Justice Department, HHS and NIH, with QTFY infrastructure compromising the Senate as recently as this year.
- QScan scanned and infected IoT devices worldwide to build QTRouter, an obfuscation botnet that let QTFY and paying customers disguise intrusions as local traffic.
- The FBI declined to tell The Register how many computers QTFY compromised in total or whether the group is linked to China's other "Typhoon" hacking crews.
Why it matters
This is a US law enforcement disruption of live hacking infrastructure tied to a Chinese state-linked group, not just an advisory. Court-ordered seizure of the three domains hardcoded into QScan and QTRouter made both tools inoperable, cutting off an operation the FBI says has run since at least 2018 and reached federal agencies as sensitive as NASA and the US Senate this year.
Who it affects
US federal agencies named as victims include NASA, the US Senate, the Department of Energy, the Federal Reserve, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health. Earlier QTFY activity also hit a medical center in Ohio, financial groups in Michigan and South Korea, a Missouri insurance agency, three DOE National Laboratories, NIH and a US security device manufacturer. Owners of IoT devices and VPN appliances remain relevant: QScan's method was to scan for and infect internet-connected devices en masse.
How to use it
The intrusions the FBI describes ran through known, previously patched flaws: CVE-2019-11510 in Ivanti's Pulse Secure VPN, patched in April 2019, and CVE-2019-19781 in Citrix VPN products, plus a zero-day against Ivanti's Cloud Services Appliance used in the 2024 lab break-ins. Organizations running any of that gear have a concrete reason to confirm those patches are applied and to check for the three now-seized domains, qtproxy.xyz, qt-proxy.org and qt-team.com, in historical network logs.
How solid is it
The account rests on court documents underlying the seizure warrants and the Justice Department's own statement that the seizures disabled both tools, which is a firmer basis than an unverified security-vendor report. The gaps are real, though: the FBI did not answer The Register's questions about the total number of compromised computers or any link between QTFY and China's other "Typhoon" groups, so those points remain open rather than confirmed either way.
Risks and caveats
No individuals have been named or indicted as QTFY members, and neither Nanjing Xinjiuwei nor the PRC government has responded to the allegations in the source material. The exact scope of several attacks, including the Ohio medical center and the Michigan, South Korea and Missouri victims, is not specified. Seizing domains disables the current infrastructure but does not guarantee the group cannot rebuild: Flax Typhoon burned down its own botnet under pressure in 2024, and a Volt Typhoon-linked botnet that the FBI disrupted in late 2023 was reported resurgent, at 1,500 devices, as recently as June.
“Payments from the PRC's Ministry of State Security (MSS) to Nanjing Xinjiuwei, for example, indicate that the company conducts malicious cyber activities on behalf of the PRC Government”
— court documents, cited by the FBI