Adversary Intelligence — 2026-08-27
DOJ Disrupts Chinese Hacking Campaign That Targeted Justice Department NASA Federal Reserve and US Senate
BLUFSeizing domains without sanctioning or indicting Nanjing Xinjiuwei leaves the PRC's paid-hacking contractor model intact and available for rapid reconstitution under fresh infrastructure.
The Justice Department and FBI announced court-authorized seizures of two domains tied to hacking platforms "QScan" and "QTRouter," used by a China-based group called QTFY to disable the malware's command infrastructure 1. According to court documents unsealed in the Southern District of California, QTFY was operated by Nanjing Xinjiuwei Network Technology Company on behalf of PRC customers including the Ministry of State Security and the People's Liberation Army 12. NASA, the Federal Reserve, the Department of Justice, and the U.S. Senate were named as targets, while an FBI affidavit lists three Department of Energy national laboratories, the National Institutes of Health, and a Department of Health and Human Services agency as confirmed victims of successful intrusions dating back to 2018 123. CNN reported the campaign also hit hospitals, universities, telecom providers, power companies, financial institutions, defense contractors, and military networks, citing the same affidavit 2. A Chinese Embassy spokesperson said Beijing "opposes and combats all forms of cyberattacks" and urged the U.S. to stop using cybersecurity to "smear or discredit" China 2.
Analysis
The seizure disables QScan and QTRouter's hard-coded domains but leaves Nanjing Xinjiuwei, the contractor the affidavit ties directly to Ministry of State Security and PLA tasking, untouched. Removing infrastructure without sanctions or indictments against the firm leaves the paid-hacking-as-a-service model intact and available for reconstitution under new domains, though the joint FBI-NSA advisory and Lumen's parallel disclosure raise the near-term cost of reusing QScan's IoT-scanning method. This is the fourth such takedown of PRC-linked infrastructure since 2023, after PlugX, Flax Typhoon, and Volt Typhoon, a pattern of technical disruption substituting for accountability against the contractors building these platforms. Reporting rests on a single primary account, DOJ's press release and the unsealed affidavit, with other outlets amplifying rather than independently verifying. The disclosure may serve as much to signal deterrence ahead of Xi Jinping's planned visit as to degrade QTFY's operating capability.
4 sources
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure - U.S. Department of Justice
- US says Chinese cyber spies targeted hospitals, government agencies and the military - CNN
- NASA, Fed, Senate among Chinese hackers' targets, Justice Department says - The Hill
- US says it disrupted Chinese hacking campaign that broke into top government bodies - Times of Israel
View in full brief →