FBI Seizes Chinese Hacking Platforms Used in Attacks on US Agencies

cryptonews.ruPubblicato 2026-08-27Pubblicato ultima volta 2026-08-27

Introduzione

On August 26, federal authorities disrupted two interconnected Chinese-state-sponsored hacker platforms, QScan and QTRouter, by seizing their domains. The platforms, operated by the group QTFY, were used to target critical U.S. infrastructure and sensitive networks at agencies including NASA, the Federal Reserve, and several U.S. Departments. The FBI asserts QTFY sold hacking services to Chinese state clients. QScan scanned for and exploited vulnerabilities in internet-connected devices, processing millions of tasks. Compromised devices were then funneled into QTRouter, which masked attack traffic by routing it through these devices and proxy services, making malicious activity appear local. This infrastructure also facilitated financially motivated cybercrime, earning operators millions. This seizure is part of a broader U.S. campaign against state-sponsored Chinese cyber infrastructure, following earlier operations against botnets like Volt Typhoon and the removal of PlugX malware. The U.S. is expanding its approach to foreign cyber threats, including a new program to enable vetted companies to conduct disruption missions. General protective measures for all users include updating software and avoiding suspicious downloads.

On August 26, federal authorities disrupted two interconnected hacking platforms, seizing the domains necessary for their communication and authentication functions. The Department of Justice announced that QScan and QTRouter targeted critical infrastructure and confidential networks managed by NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

According to court documents, these platforms belong to QTFY—a state-sponsored Chinese hacking group operating for the company Nanjing Xinjiuwei Network Technology Company. An FBI affidavit justifying the domain seizures alleges that QTFY sold hacking services to clients, which included China's Ministry of State Security and the People's Liberation Army. Three seized domains were hard-coded into the platforms, allowing the operation to take both systems offline.

The seizure disrupted infrastructure that was claimed to help hackers identify vulnerable systems and mask their connections to target networks. Attorney General Todd Blanche stated:

"Federal law enforcement has investigated and neutralized malicious PRC software—this is the latest in a series of technical operations aimed at stopping the indiscriminate hacking activity sponsored by the People's Republic of China."

QScan Identified Targets, QTRouter Masked Attacks

These two platforms performed different functions within an integrated system for intelligence gathering, vulnerability exploitation, and traffic obfuscation. In a joint cybersecurity advisory prepared by the FBI, the National Security Agency, and the Cyber National Mission Force, it is indicated that QScan contained over 200 proof-of-concept exploits and processed over 2 million scanning and penetration testing tasks in a single day in 2024. During a campaign conducted in May 2024, data was stolen from more than 300 organizations worldwide.

QScan automatically compromised vulnerable internet-connected devices and added them to QTRouter, which combined the hacked devices with commercial proxy services and rented virtual private servers. Black Lotus Labs analyzed QTFY's infrastructure and characterized the group as an infrastructure provider supporting Chinese cyber operations. Routing traffic through devices located near victims created the appearance that malicious messages originated from legitimate local users.

FBI Director Kash Patel stated:

"Today, we announced the takedown of a global botnet and hacking platform used by Chinese state-sponsored hackers to attack US critical infrastructure. These tools were used by PRC cybercriminals to conceal the source of their attacks."

Compromised routers and other Internet of Things devices were also used to carry out financially motivated cybercrimes unrelated to state-sponsored operations. Previously, authorities dismantled a proxy network that included 369,000 hacked devices in 163 countries. This network allowed criminals to mask activities related to cryptocurrency account hijacking, bank fraud, ransomware use, and other schemes, earning its operators over $5.7 million.

Operation Expands Campaign to Disrupt Infrastructure

The latest seizures follow several court-authorized operations targeting state-sponsored Chinese cyber infrastructure. In January 2025, the FBI reported removing the PlugX spyware from approximately 4,258 US systems infected by the Mustang Panda group. Federal authorities also disrupted the "Flax Typhoon" botnet in 2024 and thwarted the "Volt Typhoon" botnet in 2023.

The federal approach to foreign cyber threats also extends beyond traditional court-authorized seizures and malware removal operations. A Presidential Memorandum from August 12 mandated the creation of a federally overseen cyber threat disruption program, allowing vetted US companies to propose missions against foreign criminal networks, with officials given 60 days to establish criteria, target vetting procedures, and safety measures.

Federal investigators are increasingly blocking the accounts, servers, domains, and network connections that enable foreign cyber operations. In a separate initiative conducted in May, technology companies joined a Department of Justice operation that blocked over 1.4 million accounts linked to fraud. Participants also blocked malicious internet traffic, decommissioned hosting infrastructure, and helped freeze over $3.8 million in cryptocurrency.

Individual users face different risks than sophisticated criminal groups targeting government agencies and critical infrastructure, although both may use malware and compromised devices. Common protective measures include updating software, avoiding suspicious downloads, and verifying websites before entering sensitive information. Phishing and fake websites can install malware or reveal passwords, while outdated routers can provide attackers with infrastructure to conceal intrusions.

Domande pertinenti

QWhat were the names of the two interconnected hacker platforms disrupted by US federal authorities on August 26th, and what were their primary functions?

AThe two platforms were QScan and QTRouter. QScan functioned as a scanning tool to identify vulnerable systems, containing over 200 exploits. QTRouter was a masking infrastructure that used compromised devices to hide the origin of attacks and route traffic through them to make malicious activity appear as if it came from legitimate local users.

QAccording to the FBI affidavit, which Chinese entities were allegedly clients of the QTFY group, the operator of these platforms?

AAccording to the FBI affidavit, the alleged clients of the QTFY group included China's Ministry of State Security and the People's Liberation Army.

QBesides state-sponsored espionage, how else were the compromised routers and IoT devices used, according to the article?

AThe compromised routers and IoT devices were also used for financially motivated cybercrime unrelated to state-sponsored operations. This included schemes like cryptocurrency account takeovers, bank fraud, ransomware attacks, and other criminal activities, generating over $5.7 million for the operators.

QWhat is one of the previous botnets mentioned in the article that US authorities had taken down prior to this operation against QScan and QTRouter?

APrior to this operation, US federal authorities had taken down the 'Volt Typhoon' botnet in 2023. The article also mentions the disruption of the 'Flax Typhoon' botnet in 2024 and the removal of PlugX malware from U.S. systems in January 2025.

QWhat broader US government initiative, announced via a Presidential Memorandum in August, is mentioned as a new approach to countering foreign cyber threats beyond traditional court-authorized seizures?

AThe broader initiative is a program to disrupt cyberattacks under federal oversight, as directed by a Presidential Memorandum on August 12th. This program would allow vetted U.S. companies to conduct missions against foreign criminal networks. Officials were given 60 days to establish criteria for company selection, target vetting procedures, and safety measures.

Letture associate

Morgan Stanley Research Report Analysis: Google at a 12% Premium, Meta at a 30% Discount - Internet Giants' Valuations Diverge

In a volatile end to the summer for internet stocks, Morgan Stanley's latest valuation report highlights a significant divergence in how the market is pricing major tech giants. While the sector's average forward EV/EBITDA multiple trades below historical averages, individual company valuations are splitting, largely driven by perceived AI capabilities. Alphabet (Google) is the standout, trading at a 12% premium to its 3-year average on an EV/EBITDA basis. This premium is attributed to upward revisions for its AI hardware (TPU) sales potential, advancements in its Gemini models, and cloud margin expansion. In stark contrast, Meta trades at a deep 30% discount to its 2-year average, as concerns over social media advertising competition outweigh its progress in AI-powered ad tools. Amazon sits in the middle, trading at a moderate discount. The report notes a broader sector trend: EV/Sales multiples are expanding while EV/EBITDA multiples are contracting, indicating the market is placing a higher premium on profitability over pure revenue growth. Sub-sectors like e-commerce and digital media face the most valuation pressure. Furthermore, adjusting earnings for stock-based compensation (SBC) reveals significantly higher "true" valuation multiples across the board. Morgan Stanley concludes that valuation recovery for the internet sector will depend on upward revisions to profit estimates—driven by catalysts like new AI product cycles and cloud growth stabilization—rather than simple mean reversion. The firm maintains an "Attractive" view on the sector.

marsbit7 min fa

Morgan Stanley Research Report Analysis: Google at a 12% Premium, Meta at a 30% Discount - Internet Giants' Valuations Diverge

marsbit7 min fa

Trading

Spot
活动图片