Ethical Hacking News
The FBI has seized two platforms used by a Chinese-government backed group to hack into critical networks, including NASA and the US Senate. The seizure is a major blow to the group and its alleged backers, the PRC's Ministry of State Security. The move is part of a broader global effort to combat the growing threat of state-sponsored cyber espionage.
The FBI has seized two platforms, QScan and QTRouter, used by Chinese-government cyberoperatives to hack into critical networks. The platforms were created and operated by a PRC-backed group called QTFY, linked to the PRC's Ministry of State Security (MSS). The QTRouter botnet was used to attack numerous high-profile targets, including the US Senate, the Department of Energy, and critical infrastructure. The seizure of the platforms is a significant blow to the QTFY group and its alleged backers, the PRC's MSS. The FBI has charged numerous individuals with crimes related to their involvement with the QTFY group. The seizure is part of a broader global effort to combat state-sponsored cyber espionage.
The Federal Bureau of Investigation (FBI) has announced a significant breakthrough in its ongoing efforts to combat Chinese government-backed cyber threats. In a move that has sent shockwaves through the cybersecurity community, the FBI has seized two platforms that Chinese-government cyberoperatives used to hack into critical networks, including NASA, the US Senate, the Department of Energy, and several other government agencies and critical infrastructure.
According to court documents, the two now-seized hacking tools, QScan and QTRouter, were created and operated by a People's Republic of China (PRC)-backed group called QTFY. The group, which is believed to be linked to the PRC's Ministry of State Security (MSS), used the two platforms to conduct malicious cyber activities, including scanning and exploiting thousands of IoT devices worldwide, and then adding them to the QTRouter network of QTFY-controlled devices.
The QTRouter botnet, consisting of compromised IoT devices, commercial proxy service devices, and leased virtual private servers, served as an obfuscation network, allowing QTFY and other criminals to conceal the origin of their digital intrusion activities, making these communications appear to originate from local computers. This obfuscation network was used to attack numerous high-profile targets, including the US Senate, the Department of Energy, and several other government agencies and critical infrastructure.
The FBI's investigation into the QTFY group was sparked by reports of a People's Republic of China-backed group using a zero-day exploit to attack a medical center in Ohio during the COVID-19 pandemic. The group was also linked to a series of other attacks, including a breach of the National Institutes of Health and a zero-day attack against the Federal Reserve.
The seizure of the QScan and QTRouter platforms is a significant blow to the QTFY group and its alleged backers, the PRC's MSS. The seizure of the platforms has rendered the two tools inoperable, and is likely to be a major setback for the group's cyber operations.
This latest disruption follows a series of court-ordered seizures intended to hamstring China's hacking activities over the last few years. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 US computers that had been infected by the PRC-sponsored group Mustang Panda. A year earlier, in 2024, China's Flax Typhoon group was forced to burn down its own botnet consisting of hundreds of thousands of infected internet-of-things devices when confronted by the feds. And in late 2023, the FBI disrupted a botnet used by yet another Chinese government attack crew, Volt Typhoon, to attack US and foreign critical infrastructure.
The FBI's efforts to combat Chinese government-backed cyber threats are part of a broader global effort to combat the growing threat of state-sponsored cyber espionage. The FBI has long been a leader in the fight against cybercrime, and its efforts to combat Chinese government-backed cyber threats are a critical part of that effort.
In addition to the seizure of the QScan and QTRouter platforms, the FBI has also charged numerous individuals with crimes related to their involvement with the QTFY group. The charges include conspiracy to commit cybercrime, conspiracy to commit unauthorized access to computers, and conspiracy to commit identity theft.
The QTFY group's alleged backers, the PRC's MSS, have also been implicated in numerous cybercrime schemes, including the use of zero-day exploits to attack high-profile targets. The MSS has long been accused of conducting cyber espionage and other malicious activities on behalf of the PRC government.
The seizure of the QScan and QTRouter platforms is a significant development in the ongoing fight against Chinese government-backed cyber threats. It is a major blow to the QTFY group and its alleged backers, and is likely to be a critical setback for their cyber operations. The FBI's efforts to combat Chinese government-backed cyber threats are part of a broader global effort to combat the growing threat of state-sponsored cyber espionage.
Related Information:
https://www.ethicalhackingnews.com/articles/FBI-Cracks-Down-on-Chinese-Government-Backed-Botnets-A-Threat-to-Global-Cybersecurity-ehn.shtml
https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742
https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
https://media.defense.gov/2026/Aug/26/2003986916/-1/-1/0/JCSA_CHINA_QTFY_MALICIOUS_SYSTEMS.PDF
Published: Wed Aug 26 20:20:38 2026 by llama3.2 3B Q4_K_M