US Seizes Chinese Hacker Domains Targeting Critical Infrastructure

Acting under a federal court order, the U.S. Department of Justice seized two internet domains—QScan and QTRouter—used by a state-sponsored Chinese hacking group to target sensitive networks and critical infrastructure. The operation aimed to dismantle malicious platforms active since at least 2018.

Two internet domains utilized by state-sponsored Chinese hackers to target critical infrastructure in the United States were seized under a court order, according to a Department of Justice release on Wednesday. A San Diego federal judge authorized the domain seizure to deny malicious actors access to the platforms QScan and QTRouter. An FBI agent explained in a supporting affidavit that the hacker group QTFY created and used these two platforms to scan vulnerable devices and hide malicious network traffic.

Targeting Government Agencies and Infrastructure

According to the Department of Justice, the QTFY platforms have been used to compromise American critical infrastructure going back to at least 2018. Federal investigators stated that the hacker group used the infrastructure to spy on high-profile government agencies, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, and the Senate.

The technical mechanics of the operation relied heavily on automation. QScan scanned and automatically infected thousands of vulnerable devices worldwide, which were subsequently added to the QTRouter network, an FBI agent detailed in the affidavit. QTFY then put these devices into service through a network of infected “bots” that could be remotely controlled for various tasks, including operating from within targeted networks such as a government employee’s computer. The Department of Justice noted that these botnets were deployed specifically to obscure QTFY’s actions and its Chinese origin.

A Quartermaster Model Linked to Chinese Authorities

Investigations tie the QTFY group directly to the Nanjing Xinjiuwei Network Technology Company. According to a government advisory issued on Wednesday, the company offered these hacking platforms as branded services to customers that included the Chinese military and China’s Ministry of State Security.

A report issued by Lumen Technologies described the hacker group as operating under a quartermaster model, providing the necessary infrastructure to identify targets, route malicious traffic, and obscure activity. Because the seized domains were vital parts of the QScan and QTRouter technology, the court-ordered action rendered the tools inoperable, according to the Department of Justice.

FBI Director Kash Patel stated that cyber actors from the People’s Republic of China used these tools to conceal the origins of their attacks, adding that the day’s action was merely the latest technical operation directed against PRC-sponsored hacking and that, in support of President Trump’s Cyber Strategy for America, the FBI was intensifying its efforts to influence adversary behavior and defend the homeland within cyberspace.

Broader Cyber Conflict and Ongoing Operations

Officials from the Trump administration described the seizures as a victory in what is frequently characterized as a cyber cold war between the United States and China. Attorney General Todd Blanche emphasized that federal law enforcement investigated and disabled the software as part of a series of technical operations to dismantle state-sponsored hacking.

State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise. Todd Blanche, Attorney General

Chinese Hackers Target US Fed, Senate, NASA: DOJ Seizes Domains #shorts

In the supporting affidavit, the FBI agent noted that probable cause existed to believe the domains were involved in a money laundering scheme. Mark Remily, special agent in charge of the FBI San Diego Field Office, stated that the bureau will continue to disrupt and impose costs on cyber adversaries through complex investigations and strong partnerships.

These actions unfold against the backdrop of an unseen conflict where hackers from both nations work to gather intelligence and embed themselves in critical infrastructure. The Cybersecurity and Infrastructure Security Agency has consistently warned that Chinese hackers target sectors such as telecommunications, energy grids, and transportation.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

I Suggested the DMK-ADMK Alliance!

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.