FBI Seizes Chinese Hacking Platforms Used in Attacks on US Agencies

cryptonews.ruОпубліковано о 2026-08-27Востаннє оновлено о 2026-08-27

Анотація

On August 26, federal authorities disrupted two interconnected Chinese-state-sponsored hacker platforms, QScan and QTRouter, by seizing their domains. The platforms, operated by the group QTFY, were used to target critical U.S. infrastructure and sensitive networks at agencies including NASA, the Federal Reserve, and several U.S. Departments. The FBI asserts QTFY sold hacking services to Chinese state clients. QScan scanned for and exploited vulnerabilities in internet-connected devices, processing millions of tasks. Compromised devices were then funneled into QTRouter, which masked attack traffic by routing it through these devices and proxy services, making malicious activity appear local. This infrastructure also facilitated financially motivated cybercrime, earning operators millions. This seizure is part of a broader U.S. campaign against state-sponsored Chinese cyber infrastructure, following earlier operations against botnets like Volt Typhoon and the removal of PlugX malware. The U.S. is expanding its approach to foreign cyber threats, including a new program to enable vetted companies to conduct disruption missions. General protective measures for all users include updating software and avoiding suspicious downloads.

On August 26, federal authorities disrupted two interconnected hacking platforms, seizing the domains necessary for their communication and authentication functions. The Department of Justice announced that QScan and QTRouter targeted critical infrastructure and confidential networks managed by NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

According to court documents, these platforms belong to QTFY—a state-sponsored Chinese hacking group operating for the company Nanjing Xinjiuwei Network Technology Company. An FBI affidavit justifying the domain seizures alleges that QTFY sold hacking services to clients, which included China's Ministry of State Security and the People's Liberation Army. Three seized domains were hard-coded into the platforms, allowing the operation to take both systems offline.

The seizure disrupted infrastructure that was claimed to help hackers identify vulnerable systems and mask their connections to target networks. Attorney General Todd Blanche stated:

"Federal law enforcement has investigated and neutralized malicious PRC software—this is the latest in a series of technical operations aimed at stopping the indiscriminate hacking activity sponsored by the People's Republic of China."

QScan Identified Targets, QTRouter Masked Attacks

These two platforms performed different functions within an integrated system for intelligence gathering, vulnerability exploitation, and traffic obfuscation. In a joint cybersecurity advisory prepared by the FBI, the National Security Agency, and the Cyber National Mission Force, it is indicated that QScan contained over 200 proof-of-concept exploits and processed over 2 million scanning and penetration testing tasks in a single day in 2024. During a campaign conducted in May 2024, data was stolen from more than 300 organizations worldwide.

QScan automatically compromised vulnerable internet-connected devices and added them to QTRouter, which combined the hacked devices with commercial proxy services and rented virtual private servers. Black Lotus Labs analyzed QTFY's infrastructure and characterized the group as an infrastructure provider supporting Chinese cyber operations. Routing traffic through devices located near victims created the appearance that malicious messages originated from legitimate local users.

FBI Director Kash Patel stated:

"Today, we announced the takedown of a global botnet and hacking platform used by Chinese state-sponsored hackers to attack US critical infrastructure. These tools were used by PRC cybercriminals to conceal the source of their attacks."

Compromised routers and other Internet of Things devices were also used to carry out financially motivated cybercrimes unrelated to state-sponsored operations. Previously, authorities dismantled a proxy network that included 369,000 hacked devices in 163 countries. This network allowed criminals to mask activities related to cryptocurrency account hijacking, bank fraud, ransomware use, and other schemes, earning its operators over $5.7 million.

Operation Expands Campaign to Disrupt Infrastructure

The latest seizures follow several court-authorized operations targeting state-sponsored Chinese cyber infrastructure. In January 2025, the FBI reported removing the PlugX spyware from approximately 4,258 US systems infected by the Mustang Panda group. Federal authorities also disrupted the "Flax Typhoon" botnet in 2024 and thwarted the "Volt Typhoon" botnet in 2023.

The federal approach to foreign cyber threats also extends beyond traditional court-authorized seizures and malware removal operations. A Presidential Memorandum from August 12 mandated the creation of a federally overseen cyber threat disruption program, allowing vetted US companies to propose missions against foreign criminal networks, with officials given 60 days to establish criteria, target vetting procedures, and safety measures.

Federal investigators are increasingly blocking the accounts, servers, domains, and network connections that enable foreign cyber operations. In a separate initiative conducted in May, technology companies joined a Department of Justice operation that blocked over 1.4 million accounts linked to fraud. Participants also blocked malicious internet traffic, decommissioned hosting infrastructure, and helped freeze over $3.8 million in cryptocurrency.

Individual users face different risks than sophisticated criminal groups targeting government agencies and critical infrastructure, although both may use malware and compromised devices. Common protective measures include updating software, avoiding suspicious downloads, and verifying websites before entering sensitive information. Phishing and fake websites can install malware or reveal passwords, while outdated routers can provide attackers with infrastructure to conceal intrusions.

Пов'язані питання

QWhat were the names of the two interconnected hacker platforms disrupted by US federal authorities on August 26th, and what were their primary functions?

AThe two platforms were QScan and QTRouter. QScan functioned as a scanning tool to identify vulnerable systems, containing over 200 exploits. QTRouter was a masking infrastructure that used compromised devices to hide the origin of attacks and route traffic through them to make malicious activity appear as if it came from legitimate local users.

QAccording to the FBI affidavit, which Chinese entities were allegedly clients of the QTFY group, the operator of these platforms?

AAccording to the FBI affidavit, the alleged clients of the QTFY group included China's Ministry of State Security and the People's Liberation Army.

QBesides state-sponsored espionage, how else were the compromised routers and IoT devices used, according to the article?

AThe compromised routers and IoT devices were also used for financially motivated cybercrime unrelated to state-sponsored operations. This included schemes like cryptocurrency account takeovers, bank fraud, ransomware attacks, and other criminal activities, generating over $5.7 million for the operators.

QWhat is one of the previous botnets mentioned in the article that US authorities had taken down prior to this operation against QScan and QTRouter?

APrior to this operation, US federal authorities had taken down the 'Volt Typhoon' botnet in 2023. The article also mentions the disruption of the 'Flax Typhoon' botnet in 2024 and the removal of PlugX malware from U.S. systems in January 2025.

QWhat broader US government initiative, announced via a Presidential Memorandum in August, is mentioned as a new approach to countering foreign cyber threats beyond traditional court-authorized seizures?

AThe broader initiative is a program to disrupt cyberattacks under federal oversight, as directed by a Presidential Memorandum on August 12th. This program would allow vetted U.S. companies to conduct missions against foreign criminal networks. Officials were given 60 days to establish criteria for company selection, target vetting procedures, and safety measures.

Пов'язані матеріали

Stripe Helps Revolut Issue a Euro Stablecoin

On August 26th, Revolut announced the rollout of EURR, a new euro-pegged stablecoin, to select users in Denmark, Poland, and Portugal, with plans to expand across the European Economic Area. The stablecoin, issued 1:1 against the euro on Ethereum and Polygon, is not issued by Revolut itself. Instead, it is issued by Bridge Building S.A., a Stripe-owned, Luxembourg-based electronic money institution licensed under the MiCA framework. This structure positions Revolut as the distribution channel for its over 80 million users, while Stripe/Bridge provides the compliant issuance infrastructure and reserve management. EURR's launch is essentially a cold start, with a circulating supply of only 374 tokens. It enters a euro stablecoin market dominated by Circle's EURC and Société Générale's EURCV, which itself is a tiny fraction of the massive dollar stablecoin market led by USDT and USDC. EURR's primary advantage is Revolut's vast user base, aiming to onboard retail banking customers to on-chain finance. However, its utility for the average Revolut user, who already enjoys fast euro transfers, remains tied to specific crypto-native use cases like DeFi. The launch coincides with Revolut's MiCA-driven phasing out of USDT for European users, positioning EURR as a compliant replacement. More broadly, the partnership highlights Stripe's strategy through its Bridge acquisition: building a "stablecoin-as-a-service" or "issuance-as-a-service" platform. Stripe aims to provide the compliant backend infrastructure—issuance, reserves, redemption—allowing other companies like Revolut to launch branded stablecoins easily, potentially reshaping the industry's competitive landscape from direct token competition to infrastructure services.

marsbit5 хв тому

Stripe Helps Revolut Issue a Euro Stablecoin

marsbit5 хв тому

U.S. Financial Risks Benefit Gold and Bitcoin! Record Capital Inflow Over the Last Five Trading Days! Here's All the Data

Concerns over U.S. fiscal prospects and growing government debt are driving investors towards both gold and Bitcoin. Over the last five trading days, a record $7 billion flowed into gold and Bitcoin ETFs. Approximately $3.4 billion entered the SPDR Gold Shares (GLD) fund, while BlackRock's spot Bitcoin ETF (IBIT) saw around $1.5 billion in inflows, placing both among the top ten U.S. ETFs by weekly capital inflow. Bloomberg notes the simultaneous strong inflows into both assets as particularly remarkable, a shift from past behavior where investors typically favored gold as a safe haven during market stress. Recent investor behavior has changed due to expectations of increased U.S. government borrowing, concerns about the dollar, and policies aimed at lowering long-term interest rates, boosting demand for assets with limited supply. The concurrent rise in the value of gold and Bitcoin indicates investors are turning to alternative assets to hedge against risks within the traditional financial system, especially amid heightened debates on U.S. debt sustainability. Experts suggest this strong ETF inflow may signal that institutional investors are increasingly viewing Bitcoin as a portfolio diversification tool similar to gold, though Bitcoin's high price volatility means the risk profiles of the two assets remain significantly different.

cryptonews.ru6 хв тому

U.S. Financial Risks Benefit Gold and Bitcoin! Record Capital Inflow Over the Last Five Trading Days! Here's All the Data

cryptonews.ru6 хв тому

Tokenized Deposits Could Raise US Lending Costs: Dallas Fed Economists

Tokenized deposits could increase U.S. lending costs and make bank funding less stable, according to an analysis by Dallas Fed economists. Rosy Leigh and Sreeni Ramaswamy note that instant settlement capabilities, programmable deposit tokens, and AI could allow depositors chasing higher yields to move funds faster between banks, reducing deposit tenures and increasing their sensitivity to interest rates. The economists estimate that a 10% increase in deposit rate sensitivity could reduce banks' capacity to hold long-term loans by around $700 billion over a ten‑year equivalent. A 10% reduction in deposit tenures could lower capacity by about $580 billion. These scenarios do not imply a direct, proportional cut in lending but highlight potential pressures. U.S. banks are developing blockchain networks for moving tokenized deposits around‑the‑clock while keeping funds within the regulated banking system. Thirty‑nine state banking associations recently formed the BankChain alliance to build a nationwide network, while The Clearing House is developing a separate network with major banks. Institutions like Standard Chartered and HSBC have also tested cross‑border tokenized deposit transactions via blockchain. Banks may respond to more volatile deposits by holding more liquid assets (like reserves and Treasuries) or relying more on wholesale debt—which would likely raise borrowing costs for consumers and businesses. The authors cite Brazil's Pix instant payment system as a comparative example, where increased use raised bank liquidity holdings and reduced credit intermediation.

cryptonews.ru8 хв тому

Tokenized Deposits Could Raise US Lending Costs: Dallas Fed Economists

cryptonews.ru8 хв тому

Торгівля

Спот
活动图片