China-Linked Hackers Breach U.S. Critical Infrastructure

China-Linked Hackers Breach U.S. Critical Infrastructure

First seen 27 Aug 2026, 02:38 UTC PrimarynewssourceCbsaustinthenationaldesk.com 79.0

Article Content

Browse articles
ThreatCluster

Federal authorities announced the seizure of two hacking platforms, QScan and QTRouter, allegedly used by a China-based group known as QTFY to target U.S. critical infrastructure. The Justice Department and FBI reported that these platforms compromised networks of NASA, the Federal Reserve, and several federal departments since at least 2018. QScan infected thousands of devices worldwide, which were then integrated into the QTRouter network to obscure the source of attacks. The seized domains were integral to the malware's operation, facilitating communication and authentication. The action follows previous efforts to disrupt China-linked malware campaigns. Officials did not specify the duration of the intrusions or any resulting damages.

Key Points: • QScan and QTRouter used by China-linked hackers to target U.S. infrastructure. • Affected entities include NASA, the Federal Reserve, and multiple federal departments. • Seizure of domains rendered the hacking platforms inoperable.

Timeline

2026-08-26
DOJ announces seizure of hacking platforms
The Justice Department and FBI announced the seizure of QScan and QTRouter, used by QTFY to target U.S. networks.
thenationaldesk.com
2026-08-26
Details of the hacking operations revealed
Court documents unsealed described the operations of QTFY, targeting critical infrastructure since 2018.
Cbsaustin
2026-08-26
QScan and QTRouter made inoperable
The seizure of domains linked to the malware rendered both QScan and QTRouter inoperable, disrupting their operations.
Primarynewssource