The list of targets alone is arresting: NASA, the Federal Reserve, the US Senate, the Justice Department, and the departments of Energy and Health and Human Services. On Wednesday the DOJ and FBI said they had disrupted a Chinese hacking operation that had spent years probing those agencies, seizing the internet domains behind two malicious platforms called QScan and QTRouter. The most revealing detail, though, is not who got hit. It is who was doing the hitting.
According to unsealed court documents, the tools were built and run by a group the government calls QTFY, whose members work for a private Chinese company, Nanjing Xinjiuwei Network Technology. That firm, prosecutors say, sold its hacking services to paying customers, including China’s civilian spy agency, the Ministry of State Security, and its military, the People’s Liberation Army. In other words, this was not a rogue crew or a shadowy military unit. It was a business, with clients.
How the two tools worked together
The platforms formed a tidy division of labour. QScan was the scout, hunting across the internet for vulnerable connected devices and quietly infecting thousands of them worldwide. QTRouter turned that mesh of hijacked gadgets, along with rented servers and commercial proxies, into an obfuscation network, a way to route attacks so they appeared to originate anywhere but China, sometimes from a device sitting right next to the target. It is the same hide-in-the-noise playbook seen in other recent Chinese campaigns, and it is fiendishly hard to trace.
What made the takedown possible was a small structural flaw: the command domains were hard-coded into the malware itself, so seizing them left both tools unable to communicate or authenticate. In one court-authorised stroke, QScan and QTRouter went dark.
A win, not a knockout
Beijing’s response was the familiar one. China’s embassy said it opposes all forms of cyberattacks and accused Washington of using cybersecurity to “smear or discredit China,” a categorical denial the government issues after nearly every such allegation. The US, for its part, laid out specifics, including what it says are payments from the Ministry of State Security to the company, and detailed a trail of intrusions stretching back to at least 2018, from a failed run at NASA’s VPN in 2019 to data theft from defense contractors and universities in 2024.
It is worth being clear about what this operation did and did not achieve. Bricking two platforms is a genuine disruption, and it denies the attackers a working toolset today. But the company sits in China, well beyond the reach of American courts, and the people behind it can rebuild. As one analyst noted, the number of Chinese firms offering these “niche offensive services” has exploded over the past decade, turning state-backed hacking into something closer to an industry than a conspiracy.
That is the uncomfortable takeaway. The US can keep knocking out individual tools, and it should, but it is playing whack-a-mole against a marketplace. So how do you defend against an adversary that treats cyber-espionage as a product line with government buyers? Not with one seizure, however satisfying. The likelier answer is the unglamorous grind of patching devices, hardening the internet-of-things gear these networks feed on, and accepting that the next platform is probably already being built.
















Comments