U.S. disrupts Chinese state hacking linked to Nanjing firm
U.S. authorities disclosed that a Chinese state-sponsored hacking operation run by Nanjing Xinjiuwei Network Technology Company and linked to the QTFY group breached multiple federal agencies including NASA, the DOJ, the Federal Reserve, NIH, DOE, and the U.S. Senate dating back to 2018. The operation leveraged two hacking platforms, QScan and QTRouter, to automatically scan and infect thousands of internet-connected devices and route malicious traffic through proxies and botnets for wide-scale intrusion and concealment. The FBI and DOJ obtained court orders to seize three domains associated with these platforms, effectively disabling the infrastructure and cutting off its command-and-control network. Investigations describe QTFY as a prosecution-ready operation with PLA and Ministry of State Security ties, allegedly selling access to its services to government-aligned actors and operating a global botnet of compromised devices. Officials say the seizures disrupt a long-running campaign against critical infrastructure and aim to deter state-backed cyber intrusions, though Beijing has denied responsibility. Analysts note the case underscores the growing role of private contractors in state-sponsored hacking and the ongoing vulnerability of federal networks to IoT-based intrusions.



