The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
CRIMES

Chinese Hackers Used Hijacked Routers to Hide Attacks on NASA, Federal Reserve and US Senate Since 2018

U.S. authorities seized the infrastructure behind two hacking platforms after investigators linked them to a Chinese state-sponsored group and customers including the MSS and PLA

Chinese Hackers Used Hijacked Routers to Hide Attacks on NASA, Federal Reserve and US Senate Since 2018

U.S. authorities seized the infrastructure behind two hacking platforms after investigators linked them to a Chinese state-sponsored group and customers including the MSS and PLA

Key Takeaways
  • The FBI seizes core domains powering QScan and QTRouter, dismantling a Chinese state-sponsored hacking network active since 2018.
  • Court filings show QScan ran over 2 million daily scanning operations in 2024, compromising credentials across 300 American organizations.
  • The operation exposes how Chinese intelligence agencies like MSS contract private commercial vendors to execute wide-scale cyber reconnaissance.
Listen to this article
READY

Chinese hackers used hijacked routers, cameras and other internet-connected devices to conceal attacks against NASA, the Federal Reserve and the U.S. Senate as part of an operation dating back to at least 2018, U.S. authorities said. The Justice Department and FBI seized domains used by two platforms at the center of the operation, saying the action made them inoperable.

The platforms, QScan and QTRouter, were allegedly operated by QTFY, a Chinese state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company. Court documents identify the Department of Justice, Department of Energy, Department of Health and Human Services and National Institutes of Health among the other government targets.

Hospitals, telecommunications companies, financial institutions, power companies and defense contractors were also allegedly targeted. The operation extended beyond the United States, with four unnamed companies in the U.S. and South Korea also identified in the government filings.

Hijacked Devices Became A Cloak

QScan allegedly scanned the internet for vulnerable devices and automatically infected thousands of them. Those devices were then added to the QTRouter network, which also included commercial proxy services and leased virtual private servers.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

QTRouter functioned as an obfuscation network, allowing malicious traffic to appear as though it came from computers outside China. In some cases, the traffic could appear to originate from devices near the network being targeted, making the underlying source harder to identify.

The scale of the operation was substantial. An FBI affidavit said QScan processed more than 2 million scanning and exploitation tasks in a single day in 2024 and contained more than 200 exploit modules.

MSS And PLA Were Alleged Customers

The Justice Department said QTFY offered hacking services to paying customers including China’s Ministry of State Security and the People’s Liberation Army. Prosecutors allege that the services gave customers access to infrastructure for scanning networks, compromising vulnerable devices and concealing the origin of their operations.

The arrangement points to a model in which state-backed hackers could use an existing infrastructure rather than build their own scanning and concealment systems for each operation. Lumen Technologies’ Black Lotus Labs separately described QTFY as an infrastructure “quartermaster” supporting China-linked cyber operations.

More Than 300 U.S. Organizations Hit

An FBI affidavit alleges that QTFY exploited a newly disclosed Check Point vulnerability in 2024 and obtained settings and credentials from more than 300 U.S. organizations. The government also identified three Department of Energy national laboratories among the alleged targets.

The listed targets span government, energy, healthcare, telecommunications, finance and other critical sectors. The breadth of the targets suggests the platforms were used across multiple types of networks rather than for a single narrowly defined campaign.

What Was Actually Taken?

The U.S. government has identified the organizations it says were targeted but has not published a comprehensive assessment of the damage. It has not disclosed what information was taken from NASA, the Federal Reserve or the Senate, how long attackers maintained access to individual systems or whether every affected network has been fully remediated.

The allegations establish intrusion activity, but they do not establish that sensitive information was stolen from every organization named in the filings. The seizure of the platforms also does not by itself establish that every foothold created through them has been removed.

The FBI and National Security Agency released indicators of compromise covering QTFY activity dating back to at least 2018. FBI Director Kash Patel said the operation disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers to conceal the origin of their attacks.

FBI Took Down The Infrastructure

The seized domains were hard-coded into QScan and QTRouter and were required for functions including communication and authentication, according to the Justice Department. Taking control of those domains therefore rendered the two platforms inoperable, officials said.

The operation follows earlier U.S. efforts to disrupt China-linked botnets and malware infrastructure. The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers in 2025, disabled a large IoT botnet linked to Flax Typhoon in 2024 and disrupted infrastructure used by Volt Typhoon in 2023.

China’s embassy in Washington did not provide any comment on the issue, while Beijing has repeatedly denied allegations that it sponsors cyberattacks against foreign governments and organizations.

The latest seizure disrupts the platforms identified by U.S. investigators, but it does not provide a public accounting of the full impact on the organizations allegedly targeted. The government has yet to disclose how much access the hackers obtained or what data, if any, was ultimately removed from the named networks.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is QTRouter?

QTRouter is an obfuscation network developed by Nanjing Xinjiuwei Network Technology Company to conceal state-sponsored cyber operations. Court records show the software routed malicious traffic through hijacked commercial routers and cameras across the globe. The tool enabled Chinese operators to disguise intrusion attempts as local, benign internet traffic.
02

Why does this breach matter for critical US infrastructure?

The intrusion compromised perimeter settings across critical institutions including NASA, the Federal Reserve, and the Department of Energy. An FBI affidavit confirms attackers exploited a 2024 Check Point vulnerability to harvest credentials from 300 entities. Gaining access to national laboratories gives foreign intelligence deep visibility into federal research and economic networks.
03

How did the FBI take down the hacking network?

The Department of Justice seized primary web domains hard-coded into the command architecture of QScan and QTRouter. Those domains handled authentication and communication protocols dating back to initial deployments in 2018. Revoking control over these server endpoints rendered the broader botnet infrastructure inoperable for overseas operators.
04

What are the lingering risks after the domain seizures?

Federal authorities have not verified whether intruders maintain persistent backdoors inside previously breached internal networks. Black Lotus Labs identified the contractor QTFY as a commercial quartermaster supplying exploits to China's Ministry of State Security. Disabling the routing network stops active proxy relays without automatically purging malware already embedded on target servers.
05

How do commercial contractors support Chinese state intelligence?

Private tech firms like Nanjing Xinjiuwei build offensive toolkits sold directly to the People's Liberation Army. The Justice Department found QTFY maintained over 200 custom exploit modules available for military and intelligence task orders. This outsourcing model allows state agencies to launch attacks rapidly without developing unique malware pipelines in-house.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.