Key facts
- The U.S. seized two Chinese state-sponsored hacking platforms, QScan and QTRouter.
- These platforms were used to target U.S. critical infrastructure and sensitive networks.
- Victims included NASA, the Federal Reserve, NIH, and the U.S. Senate.
- The hacking group QTFY, employed by Nanjing Xinjiuwei Network Technology Company, operated the platforms.
- The platforms helped conceal the origin of cyberattacks by using compromised IoT devices and proxy services.
The United States has seized two Chinese state-sponsored hacking platforms, QScan and QTRouter, used to target U.S. critical infrastructure and other sensitive networks. The Justice Department and FBI announced the court-authorized domain seizures, which deny malicious cyber actors access to these tools.
According to court documents, a People's Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated these platforms. Among the victims of QTFY's computer intrusion activities were the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
These platforms were used to hide the origin of cyberattacks. QScan scans and infects internet-of-things (IoT) devices globally, adding them to the QTRouter network. QTRouter then serves as an obfuscation network, making malicious communications appear to originate from outside the PRC. QTFY reportedly offers computer hacking services to entities including China's Ministry of State Security and the People's Liberation Army.
