-
The Justice Department and FBI seized two hacking tools built and run by a China-based hacking group.
-
The tools, known as QScan and QTRouter, infected everyday devices like routers and cameras, then used them to hide attacks on U.S. agencies.
-
Victims allegedly include NASA, the Federal Reserve, the Department of Energy, and other major U.S. offices since 2018.

News of a major cybercrime bust spread fast on X on May 31. The account International Cyber Digest posted that the DOJ and FBI had seized infrastructure tied to a Chinese state-backed hacking group. The post said the group infected thousands of routers, cameras, and smart home devices. Attackers then used those devices to hide break-ins at NASA, the Federal Reserve, and other agencies.
The Justice Department later confirmed the news in an official announcement. Officials said they had taken down two hacking platforms used against American critical infrastructure. The case has already stirred reactions online, with one user joking about “computer stuff” running hot in a server room, while another user shared how a cheap home camera once moved and recorded on its own at night.
How the Hacking Network Worked
Court papers unsealed in the Southern District of California named the group behind the attacks. Investigators call it QTFY. The group works for a China-based firm called Nanjing Xinjiuwei Network Technology Company. According to the DOJ, QTFY built and ran two hacking tools called QScan and QTRouter.
QScan scans the internet and infects thousands of smart devices, such as routers and cameras. Once infected, these gadgets get added to a larger hacking web called QTRouter. QTRouter mixes those infected devices with rented servers and other tools bought from proxy services.
Together, the two tools form what officials call an obfuscation network. In simple terms, it hides where an attack truly comes from. A hacker sitting in China could launch an attack that looks like it came from a device in the victim’s own city. That trick made it hard for investigators to trace the true source for years.
The alleged victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
Investigators say the DOJ and FBI seized domain names that both hacking tools depended on. Since QScan and QTRouter needed those domains to communicate and log in, the seizure knocked both tools offline for good.
Officials Speak Out on the Takedown
Attorney General Todd Blanche said state-backed hackers who target America’s key systems will be stopped and prosecuted. He said the government will use every tool available to keep the country secure.
FBI Director Kash Patel said the operation dismantled a global network of hijacked devices tied to Chinese state hackers. He explained that the tools let attackers hide where their break-ins truly came from.
Patel credited the FBI’s San Diego office, its Cyber Division, and Justice Department partners for shutting the platforms down. He added that the FBI is ramping up efforts to defend the country online, as part of the current national cyber strategy.
Assistant Attorney General John Eisenberg said the seizures show the department’s steady push to fight cyber threats before they cause harm. He noted that removing these tools blocks China-linked hackers from hitting U.S. infrastructure again.
U.S. Attorney Adam Gordon said the operation protects everyday services that Americans depend on from state-backed cybercriminals. FBI Special Agent in Charge Mark Remily added that the San Diego field office stays firm in tracking down state-sponsored hackers. He said tough investigations and strong partnerships help the FBI find, stop, and punish these cyber threats.
Part of a Longer Pattern of Chinese Cyberattacks
This is not the first time U.S. agencies have taken down a China-linked hacking operation. In 2025, the FBI removed harmful spy software called PlugX from more than 4,000 American computers. That malware had been planted by a Chinese hacking group known as Mustang Panda.
In 2024, the FBI dismantled a huge network of hijacked smart devices. A Chinese group called Flax Typhoon had been renting that network out to Chinese government clients. And in 2023, the FBI broke up a separate hacking network run by a group called Volt Typhoon, which had been used to hide attacks on American and foreign infrastructure.
Alongside this week’s announcement, the FBI and the National Security Agency released a new advisory. It lists warning signs of QTFY hacking activity, based on attacks tracked back to 2018. Separately, cybersecurity firm Lumen Technologies published its own report through its Black Lotus Labs research team, describing QTFY’s methods in detail.
Cisco Talos linked China-aligned group UAT-8302 to attacks on government organizations in South America and southeastern Europe. The group uses custom malware, including CloudSorcerer and NetDraft, also seen in other China-linked campaigns.
The FBI’s San Diego Field Office, its Cyber Division, the United States Attorney’s Office for California’s Southern District, and the National Security Cyber Section of the Justice Department all worked on the case. Officials say the takedown marks the latest step in an ongoing effort to counter state-sponsored hacking from China.
For now, security researchers recommend that people using smart home devices, such as routers and cameras, change default passwords right away. Keeping device software updated also lowers the risk of becoming part of a hidden hacking network like this one.