Critical Infrastructure Security, Government security, Governance, Risk and Compliance

US denies access to China-linked group behind hacking federal agencies

China Bans Cyber Attacks: Examining Internet Security with Chinese Flag and Binary Data Through a Magnifying Glass Concept

The Department of Justice (DOJ) and the FBI on Aug. 26 said they made court-authorized seizures to deny China-linked cyber actors access to two platforms used to target U.S. critical infrastructure and sensitive federal agency networks.

According to the DOJ and FBI, a People’s Republic of China state-sponsored group known as QTFY employed by China-based Nanjing Xinjiuwei Network Technology Company created and operated the two platforms seized: QScan and QTRouter.

In malicious activity that dates back to at least 2018 and was part of a long-term Chinese government espionage strategy, QScan and QTRouter breached the networks of the DOJ, the Federal Reserve System, the National Aeronautics and Space Administration (NASA), the Department of Energy (DOE), the Department of Justice (DOJ), the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and the U.S. Senate.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said Attorney General Todd Blanche. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

Security pros commended the federal government’s efforts, but cautioned the security industry, the government, and the general public that’s there’s much work ahead.

Agnidipta Sarkar, chief evangelist at ColorTokens, said all such takedown efforts are commendable because they do hurt threat groups with malicious intent.

Sarkar said they act as a constant "tax" on the adversary and by routinely destroying the hackers' tools, stealing their victim data, and forcing them to rebuild their infrastructure from scratch, the U.S. raises the cost of cyber espionage. Sarkar added it prevents adversaries from operating with impunity and limits their ability to launch massive, coordinated, and destructive cyberattacks — such as sabotaging the U.S. power grid — by keeping them bogged down in a continuous game of digital cat-and-mouse.

“But these are short-term gains,” said Sarkar. “The reality of a ‘whack-a-mole’ action is that most state-sponsored groups have virtually unlimited funding and manpower.

Sarkar pointed out that the FBI disrupted Volt Typhoon in 2023, Flax Typhoon in 2024, PlugX in 2025, and now QTFY in 2026. As long as consumers and corporations fail to update their technology and use modern technologies like microsegmentation or build safety nets to protect vulnerable systems, hackers will always have a vast supply of vulnerable devices, he continued.

Harry Thomas, co-founder and CTO at Frenos, said the DOJ/FBI action will have a real impact, but it’s disruption — not the full defeat of the adversary. Thomas said QScan and QTRouter were not just individual servers, they formed a shared scanning and obfuscation layer that let Chinese state-linked operators identify targets, route activity through compromised devices, and conceal where attacks originated.

“Taking that infrastructure offline should slow multiple operations at once, burn established access routes, and force the actors to rebuild,” said Thomas.

Thomas pointed out that the industry has seen this pattern before: when U.S. authorities disrupted the KV Botnet used by Volt Typhoon in early 2024, they removed a genuine operational capability. But within months, Thomas said Volt Typhoon was separately observed exploiting different network infrastructure at service providers.

“That’s the reality with a well-resourced state adversary: infrastructure takedowns impose costs and buy defenders time, but they do not eliminate the people, expertise, or strategic objective behind the campaign,” said Thomas. “The broader Chinese cyber program has been operating against strategic sectors for at least two decades, even though this specific QTFY operation dates to 2018.”

Thomas added that any lasting impact will depend on what critical-infrastructure operators do with the time this disruption creates. Thomas said they should use the published indicators to look backward for compromise and identify the attack paths from internet-facing routers, VPNs, vendor connections, and other edge systems into their most critical operational environments.

“Otherwise, the adversary will rebuild the relay network and return through a different path,” said Thomas.

Unsecure OT and critical infrastructure at issue

John Gallagher, vice president at Viakoo, noted that while these takedowns have a short-term impact, they don’t always address the longer-term issue of insecure OT and critical infrastructure.  

Gallagher said because this has been a multi-year and strategic campaign on the part of the Chinese, this action will not stop it. It’s more likely that QScan or QTRouter will just resurface in a different form. 

The real issue security teams must address is that after a multi-year cybersecurity campaign there are now vast numbers of infected devices that teams must remediate and patch. Gallagher said the industry needs to focus on this to ensure that security teams can neutralize the malware already deployed. 

“The takeaway to all organizations who operate OT and IoT devices is to automate firmware patches and password rotations to harden devices that today are relatively insecure and are open targets to threat actors,” said Gallagher.

John Strand, owner of Black Hills Information Security, added while the takedown won’t dramatically change the threat landscape overnight, it does show that the United States takes these threats seriously and needs to continue putting more resources behind these efforts.

Strand explained that these nation-state attacks can look fundamentally different from the attacks that dominate the headlines. Strand said the adversaries here aren’t necessarily trying to break in and destroy something: they’re not always trying to deploy ransomware or make their presence immediately obvious, they may want to get into an environment and quietly remain there for an extended period of time.

“Unfortunately, I don’t think much of the security technology industry is focused enough on that problem,” said Strand. “It isn’t flashy. It doesn’t necessarily produce the dramatic alerts and dashboards that are easy to sell. So I think this takedown is a step in the right direction. It raises awareness. But we need to keep focusing on nation-state adversaries and, specifically, how their objectives, techniques, and indicators can be fundamentally different from the attacks that make the news every week.”

Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds