Chinese state-linked cyber-espionage network dismantled, affecting key U.S. institutions
The Department of Justice and the FBI have dealt a decisive blow to international cyber-espionage operations. U.S. authorities confirmed the dismantling of a sophisticated hacking network sponsored by the Chinese state, which managed to infiltrate highly sensitive systems, including NASA, the Senate, the Federal Reserve, and various U.S. government departments.
How did the cyber-espionage network operate?
The investigation revealed that the responsible group, identified as “QTFY” and linked to the company Nanjing Xinjiuwei Network Technology Company, operated through two main platforms called “QScan” and “QTRouter”. The operation of this scheme allowed for the concealment of the actual origin of the attacks:
- QScan: It was responsible for automatically scanning and compromising thousands of Internet of Things (IoT) devices globally.
- QTRouter: It functioned as an obfuscation network, making malicious traffic appear to originate from devices outside of China, thus making its detection difficult.
By seizing the domains embedded in the malware, federal authorities managed to disable the infrastructure of these attackers, who had been compromising critical networks since at least 2018.
Malicious state-sponsored hackers attacking America’s critical infrastructure will be stopped and prosecuted.
Attorney General Todd Blanche
A pattern of constant attacks
Court documents indicate that QTFY’s services were not only used by the group, but were available to high-level clients, including the Chinese Ministry of State Security and the People’s Liberation Army (PLA). Confirmed victims also include the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, as well as private companies in South Korea and the United States.
This operation is in addition to a series of preventive actions by the U.S. government to curb digital interference. In recent years, the FBI has dismantled networks linked to groups such as Mustang Panda, Flax Typhoon, and Volt Typhoon, demonstrating a sustained effort against cyber espionage. Cybersecurity experts, such as Dakota Cary of SentinelOne, have warned that the use of private contractors by Chinese government agencies to carry out offensive attacks is a trend that has grown significantly in the last decade.
So far, Beijing has denied any involvement in these activities, maintaining its usual stance regarding cyber espionage accusations, while U.S. authorities continue to strengthen the security of their strategic assets.








