The Department of Justice (DOJ) and the FBI on Aug. 26 said they made court-authorized seizures to deny China-linked cyber actors access to two platforms used to target U.S. critical infrastructure and sensitive federal agency networks.According to the DOJ and FBI, a People’s Republic of China state-sponsored group known as QTFY employed by China-based Nanjing Xinjiuwei Network Technology Company created and operated the two platforms seized: QScan and QTRouter.In malicious activity that dates back to at least 2018 and was part of a long-term Chinese government espionage strategy, QScan and QTRouter breached the networks of the DOJ, the Federal Reserve System, the National Aeronautics and Space Administration (NASA), the Department of Energy (DOE), the Department of Justice (DOJ), the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and the U.S. Senate.“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said Attorney General Todd Blanche. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”Security pros commended the federal government’s efforts, but cautioned the security industry, the government, and the general public that’s there’s much work ahead.Agnidipta Sarkar, chief evangelist at ColorTokens, said all such takedown efforts are commendable because they do hurt threat groups with malicious intent.Sarkar said they act as a constant "tax" on the adversary and by routinely destroying the hackers' tools, stealing their victim data, and forcing them to rebuild their infrastructure from scratch, the U.S. raises the cost of cyber espionage. Sarkar added it prevents adversaries from operating with impunity and limits their ability to launch massive, coordinated, and destructive cyberattacks — such as sabotaging the U.S. power grid — by keeping them bogged down in a continuous game of digital cat-and-mouse.“But these are short-term gains,” said Sarkar. “The reality of a ‘whack-a-mole’ action is that most state-sponsored groups have virtually unlimited funding and manpower.Sarkar pointed out that the FBI disrupted Volt Typhoon in 2023, Flax Typhoon in 2024, PlugX in 2025, and now QTFY in 2026. As long as consumers and corporations fail to update their technology and use modern technologies like microsegmentation or build safety nets to protect vulnerable systems, hackers will always have a vast supply of vulnerable devices, he continued.Harry Thomas, co-founder and CTO at Frenos, said the DOJ/FBI action will have a real impact, but it’s disruption — not the full defeat of the adversary. Thomas said QScan and QTRouter were not just individual servers, they formed a shared scanning and obfuscation layer that let Chinese state-linked operators identify targets, route activity through compromised devices, and conceal where attacks originated.“Taking that infrastructure offline should slow multiple operations at once, burn established access routes, and force the actors to rebuild,” said Thomas.Thomas pointed out that the industry has seen this pattern before: when U.S. authorities disrupted the KV Botnet used by Volt Typhoon in early 2024, they removed a genuine operational capability. But within months, Thomas said Volt Typhoon was separately observed exploiting different network infrastructure at service providers.“That’s the reality with a well-resourced state adversary: infrastructure takedowns impose costs and buy defenders time, but they do not eliminate the people, expertise, or strategic objective behind the campaign,” said Thomas. “The broader Chinese cyber program has been operating against strategic sectors for at least two decades, even though this specific QTFY operation dates to 2018.”Thomas added that any lasting impact will depend on what critical-infrastructure operators do with the time this disruption creates. Thomas said they should use the published indicators to look backward for compromise and identify the attack paths from internet-facing routers, VPNs, vendor connections, and other edge systems into their most critical operational environments.“Otherwise, the adversary will rebuild the relay network and return through a different path,” said Thomas.
Critical Infrastructure Security, Government security, Governance, Risk and Compliance
US denies access to China-linked group behind hacking federal agencies
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds