US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday.
The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China’s Ministry of State Security and the People’s Liberation Army, the department said in an affidavit. The targeted agencies included the Federal Reserve, Department of Energy, the DOJ itself, the U.S. Senate and NASA.
QScan was used by hackers to scan and automatically infect internet of things devices around the world, the DOJ said, while QTRouter served as an obfuscation network that allowed malicious actors to conceal the origin of their attacks by making it appear that actions came from any of the infected devices.
The tools allegedly enabled Chinese actors to make it look like the cyberattacks were coming from other countries and in some cases made it seem like the incidents were caused by local attackers.
The tools were used by a state-sponsored group known as “QTFY” that targeted U.S. critical infrastructure and other sensitive networks, the Justice Department said. The affidavit said other victims include the Department of Health and Human Services, the National Institutes of Health and multiple hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
FBI Assistant Director Brett Leatherman said that QTFY exploited devices in more than 130 countries and “operates within a complex network of hackers-for-hire and government clients in China.
Nanjing Xinjiuwei “sells stolen data and hacking services to Chinese military and intelligence agencies,” he said. “Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet or a network of machines secretly controlled by the adversary.”
Investigators said they have been investigating QTFY’s infrastructure since 2018 and continued until an attack on the U.S. Senate, which occurred this year. The affidavit does not explain whether specific senators or committees were attacked and the DOJ did not respond to requests for comment.
The FBI and DOJ said the takedown made both QScan and QTRouter inoperable because the seized domains were hard-coded into both platforms and used for essential tasks like communication and authentication.
The FBI said QTFY also had unspecified customers outside of the Chinese government.
One of the first attacks investigated by the FBI was a 2019 incident at NASA. Hackers attempted to exploit a vulnerability in Pulse Secure VPN. Investigators traced the IP addresses used in the NASA attack back to locations and email addresses in China.
The Justice Department and FBI have repeatedly targeted similar platforms used by state-backed hackers to obfuscate their cyberattacks on U.S. institutions. U.S. law enforcement previously obtained court orders that allowed government agents to go into devices and remove malware installed by hackers from both China and Russia.
Last year, the FBI removed the PlugX surveillance malware from thousands of U.S. computers and disrupted multiple botnets in 2024 that were run by prolific Chinese government hacking operations known as Volt Typhoon and Flax Typhoon.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



