Skip to content
China Hacked NASA, Federal Reserve: FBI Seizes Platforms Behind Eight

China Hacked NASA, Federal Reserve: FBI Seizes Platforms Behind Eight

Techtimes August 27, 2026

The Department of Justice and FBI announced on August 26 that they had seized three internet domains hard-coded into two Chinese state- hacking platforms, instantly disabling an eight-year espionage operation that had successfully penetrated NASA, the Federal Reserve, the Department of Energy, the National Institutes of Health, and the Justice Department itself. The group behind the platforms — known in court documents as QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company — sold its hacking services to MSS and PLA: China's Ministry of State Security and the People's Liberation Army.

The operation, documented in a court affidavit unsealed in the Southern District of California, stretched from at least May 2018 through June 2026, when QTFY actors scanned a U.S. election system — an attempt that failed to breach election networks . What distinguishes this action from prior Chinese hacking disclosures is what the DOJ did to stop it: three domain names, baked directly into both platforms' malware code, were seized by court order, and both platforms went dark simultaneously.

QTFY was not a conventional hacking group operating on its own initiative. It was a commercial contractor whose customers, according to court documents, included China's two most powerful intelligence and military organizations.

Nanjing Xinjiuwei — the company that employed QTFY — received direct payments from the MSS, which prosecutors stated conducts malicious cyber activities on behalf of the Chinese government. The group's roster included former People's Liberation Army officers who used their military relationships to secure contracts and subcontracts targeting critical infrastructure.

QTFY also participated in China's freelance cyber-exploit brokering market, buying and selling compromised network access on open markets alongside its state-contracted work. The FBI's characterization of the group as a "hackers for hire" network underscores that this was not an improvised operation but an industrialized service model — one that Lumen Technologies' threat intelligence arm, Black Lotus Labs, described as a digital quartermaster infrastructure model providing shared infrastructure to multiple downstream operators simultaneously.

"The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations," Lumen stated in its technical report. "By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state- actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale."

QScan and QTRouter were complementary platforms with distinct roles in a coordinated attack chain.

QScan operated as an automated scanning exploitation platform . It continuously scanned the internet for vulnerable IoT devices — routers, IP cameras, smart appliances, network-attached storage units — and exploited them at scale to absorb them into QTFY's controlled device pool. The platform used a distributed task architecture: a management domain dispatched scanning assignments to leased virtual private servers outside China, collected their results, and fed newly compromised devices into the QTRouter network.

QTRouter was the obfuscation layer. Running custom OpenWrt firmware on compromised consumer routers, it used Clash — open-source proxy chaining software — to build encrypted tunnels masked Chinese attack traffic . QTRouter nodes included not just compromised devices but also Alibaba Cloud addresses and paid subscriptions to a commercial proxy service called Fastlink — a Chinese consumer VPN product designed to circumvent the Great Firewall. By purchasing high-tier Fastlink corporate proxy subscriptions , QTFY gained access to a rotating pool of residential and commercial IP addresses that automatically defeated static IP-based security defenses.

The result: when QTFY attacked a federal agency's network, the traffic arrived appearing to originate from a residential router down the street, from a cloud service provider, or from a commercial VPN node. " QTRouter makes malicious activity difficult to identify and track," the FBI's advisory stated flatly.

Beyond the proxy network, QTFY had a documented arsenal of vulnerabilities it used to establish initial access. Court records list exploitation of CVE flaws in enterprise products including Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, CrushFTP, Ivanti Cloud Services Appliances, and BeyondTrust Remote Support — a who's who of enterprise infrastructure products, spanning vulnerabilities from 2018 through 2026. The pattern confirms what security researchers have documented repeatedly: nation-state actors do not need zero-days when N-day vulnerabilities — patched but undeployed — provide more than sufficient access to organizations that have not updated their software.

The use of consumer IoT devices as relay points is not accidental — it is the core innovation that made QTFY's campaigns difficult to detect and block.

When a compromised router in the same city as a target organization becomes a relay node for an attack, the defending security team sees local residential IP address traffic, not traffic from China. Standard defenses — country-based IP blocking, geolocation filtering — provide no protection. The device owner has no knowledge the router has been recruited into a foreign intelligence operation. The manufacturer bears no liability. And because QTRouter's node pool rotates continuously, blocking any specific compromised device simply forces QTFY to route through one of the thousands of other devices already in the pool.

Damon Rouse, a security researcher at Lumen Black Lotus Labs who tracked QTFY for 18 months before the seizure, noted that the group's target priorities extended well beyond government agencies. "The targeting was throughout the western world and beyond, especially with regard to academia," Rouse told The Hacker News . "They just love hitting research communities given the collaborative nature of advanced science."

That observation reframes the victim list. The seven named federal agencies targeted — NASA, the Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate — represent the highest-profile tier of a much broader targeting sweep that also included hospitals, universities, telecom providers, power companies, financial institutions, and defense contractors.

The technical mechanism of the seizure is what separates this action from a typical law enforcement announcement.

QTFY built QScan and QTRouter around specific hard-coded domain names that the malware depended on for essential tasks such as communication and authentication, according to court documents unsealed in California. Those domains — qtproxy[.]xyz , qt-proxy[.]org , and qt-team[.]com — were baked into the malware's code rather than stored in a remotely configurable registry. That design choice, presumably made to ensure operational reliability, turned out to be a fatal engineering vulnerability: it created a fixed dependency that could not be patched, updated, or replaced without rebuilding both platforms from scratch.

The DOJ separately noted money laundering conspiracy probable cause — suggesting financial crimes may accompany any future indictments.

This technique — the "domain keystone seizure" — is emerging as a repeatable legal-technical mechanism for disabling entire classes of shared Chinese state hacking infrastructure. It is legally clean, technically precise, and leaves no room for the operator to recover the capability without rebuilding the platforms from scratch on new domains. The three prior PRC takedowns documented in the DOJ announcement — court-authorized PlugX botnet disruptions (PlugX/Mustang Panda in 2025, Flax Typhoon in 2024, Volt Typhoon in 2023) — used variations of this approach, but QTFY is the first documented case where the target was a shared multi-tenant infrastructure supplier serving both the MSS and PLA simultaneously.

The QTFY investigation since 2019 has been underway at the FBI, and the joint cybersecurity advisory published by the FBI and NSA alongside the seizure provides indicators of compromise dating back to May 2018.

The affidavit documents a series of intrusions and targeting attempts with varying degrees of success. In August 2019, QTFY actors attempted a 2019 NASA VPN exploitation attempt — that attempt was unsuccessful. In September 2024, the group conducted DOE labs NIH HHS breaches — successfully intruding into three unnamed Department of Energy laboratories, an NIH facility, an HHS agency, and an unnamed U.S. security device manufacturer.

In March 2026, QTFY conducted a Senate hospital scan unsuccessful — officials confirmed that attempt did not successfully breach Senate networks. In June 2026, QTFY targeted an unidentified U.S. election system scan unsuccessful, per the advisory.

The DOJ's press release lists both NASA and the U.S. Senate among "victims of QTFY computer intrusion activity" — precise language that acknowledges targeting and some level of impact, but does not specify which specific intrusion attempts succeeded and which did not for each agency. What the DOJ has not disclosed publicly is what data left which agencies, how long access persisted in successfully compromised networks, or the full operational damage across eight-plus years of campaigns.

For organizations trying to defend their own networks, the QTFY takedown carries specific, actionable implications.

The FBI and NSA have published a joint cybersecurity advisory with FBI NSA advisory indicators of compromise , available at the Internet Crime Complaint Center. Lumen's Black Lotus Labs separately published a detailed breakdown of QTFY's tactics, techniques, and procedures, including network indicators defenders can use to audit their own environments.

The QTFY vulnerability arsenal and patching listed in the advisory spans eight years of enterprise security advisories. Every product named — Fortinet, Citrix, Exchange, F5, Log4j, Confluence, Check Point, CrushFTP, Ivanti, BeyondTrust — has issued patches for the relevant CVEs. The common denominator in successful QTFY intrusions was not zero-day vulnerability exploitation; it was the presence of unpatched systems in production environments. Applying outstanding patches for these products removes the technical entry points QTFY depended on.

For IoT specifically: routers, IP cameras, smart devices, and network-attached storage units that QTFY used as proxy nodes were compromised because they ran outdated firmware, used default credentials, or had management interfaces exposed to the internet. IoT firmware and reboot mitigation removes temporary malware infections in many cases; updating firmware closes the vulnerabilities that enabled reinfection; disabling remote management interfaces eliminates external attack surface. Comparing device behavior against the QTFY indicators of compromise published in the advisory will identify whether any devices in an enterprise or network were recruited into the QTRouter pool.

Nanjing Xinjiuwei's confirmed MSS payment relationship and the former PLA membership of QTFY actors place the company squarely within the legal framework China uses to direct private-sector cyber activity.

China's National Intelligence Law (2017), Article 7 intelligence cooperation mandate , requires that "all organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law." Article 14 grants intelligence agencies authority to demand that cooperation. China's Data Security Law (2021) and Cybersecurity Law (2017) add additional government-access provisions covering cross-border data handling and data localization.

For Nanjing Xinjiuwei, that legal architecture is redundant — court documents confirm the company received direct MSS payments for its hacking services, establishing the government relationship explicitly rather than through legal compulsion. But the broader implication matters for any Chinese-headquartered technology company: the intelligence cooperation obligation is a fixed legal condition, not a business decision, not subject to contractual override, and not mitigated by the physical location of servers or the existence of a Western corporate structure.

The DOJ has not publicly disclosed what data was exfiltrated, how long QTFY maintained access in successfully compromised networks, or the full operational damage from eight-plus years of campaigns. The press release DOJ confirms platforms now inoperable confirms which agencies were among victims of QTFY intrusion activity but does not detail what was taken. The gap is deliberate — ongoing intelligence and counterintelligence equities almost certainly limit what the government will say publicly. What the DOJ has confirmed is that both QScan and QTRouter are now inoperable, which removes QTFY's ability to conduct further operations using these specific platforms.

The FBI and NSA published a joint cybersecurity advisory on August 26 with FBI NSA QTFY indicators of compromise , available at ic3.gov. Those indicators include specific domain names, IP addresses, and file hashes associated with QTRouter node activity. For most users, the most practical steps are: reboot your router (this flushes temporary malware from memory in most architectures); apply any pending firmware update from your router manufacturer; disable remote management interfaces if they are enabled; and consider replacing consumer-grade routers that no longer receive security updates. The seizure of the three QTFY command-and-control domains means that any router already enrolled in the QTRouter network lost with its operators as of August 26 — but a compromised device without updated firmware remains vulnerable to re-enrollment in future botnet operations.

No individual indictments were announced alongside the domain seizures. The DOJ has established a pattern of pairing technical disruptions with eventual criminal charges — i-Soon employees were indicted in March 2025 after the i-Soon data leak, and the Treasury sanctioned Sichuan Juxinhe Network Technology in January 2025 for its role in Salt Typhoon telecom intrusions. Court documents in the QTFY case DOJ identifies MSS payment evidence of specific Nanjing Xinjiuwei MSS payment relationships and the former PLA membership of QTFY actors — both categories of evidence that have supported prior U.S. enforcement actions against Chinese cyber contractors. Whether charges follow depends on factors the DOJ has not disclosed publicly, including the identities of specific individuals and ongoing intelligence considerations.