Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

FBI Disrupts Chinese State-Sponsored Hackers' Global Infrastructure for Stealing U.S. Data




The Federal Bureau of Investigation (FBI) recently announced the disruption of two hacking platforms, QScan and QTRouter, operated by Chinese threat actors, QTFY, to target critical infrastructure and sensitive networks in the United States. The disruption marks a significant development in the ongoing efforts to combat cyber espionage and protect the nation's critical infrastructure from unauthorized access. The use of these platforms by QTFY highlights the threat posed by Chinese state-sponsored hacking to U.S. critical infrastructure and national security, emphasizing the need for increased awareness and education among U.S. organizations about the risks posed by Chinese cyber espionage.

  • The FBI disrupted two hacking platforms, QScan and QTRouter, operated by Chinese threat actors QTFY to target critical infrastructure and sensitive networks in the US.
  • QTFY, a Chinese state-sponsored group, used the platforms to steal data from various US organizations, including NASA, the Federal Reserve, and the US Senate.
  • The disruption of QScan and QTRouter platforms indicates a significant escalation in the scope and sophistication of Chinese state-sponsored hacking operations.
  • The platforms allowed QTFY to scan and infect IoT devices worldwide, adding them to the QTRouter network and concealing the true origins of their computer intrusion activities.
  • The FBI's disruption of QScan and QTRouter platforms is a significant blow to QTFY's operations, as the seized domains were hard-coded into both products, causing them to cease operations.
  • The incident highlights the need for increased awareness and education among US organizations about the risks posed by Chinese state-sponsored hacking.
  • The FBI's disruption of QScan and QTRouter platforms demonstrates the agency's ability to track and disrupt the activities of sophisticated Chinese state-sponsored hackers, emphasizing the importance of international cooperation and information sharing.



  • The Federal Bureau of Investigation (FBI) recently announced the disruption of two hacking platforms, QScan and QTRouter, operated by Chinese threat actors, QTFY, to target critical infrastructure and sensitive networks in the United States. The FBI's announcement marks a significant development in the ongoing efforts to combat cyber espionage and protect the nation's critical infrastructure from unauthorized access.

    According to the FBI, QScan and QTRouter were used by QTFY, a Chinese state-sponsored group, to steal data from various U.S. organizations, including the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. The FBI attributed the activities of QTFY to Nanjing Xinjiuwei Network Technology Company, a Chinese company with alleged ties to the Chinese Ministry of State Security and the People's Liberation Army.

    The FBI's disruption of QScan and QTRouter platforms indicates a significant escalation in the scope and sophistication of Chinese state-sponsored hacking operations. The use of these platforms to steal data from U.S. organizations highlights the threat posed by Chinese cyber espionage to the nation's critical infrastructure and national security.

    The QScan platform, in particular, is notable for its ability to scan and automatically infect IoT devices worldwide, adding them to the QTRouter network. QTRouter serves as an obfuscation network that allows QTFY and other Chinese cyber actors to conceal the true origins of their computer intrusion activities, making it challenging to identify and track malicious activity.

    The FBI's disruption of QScan and QTRouter platforms is a significant blow to QTFY's operations, as the seized domains were hard-coded into both products, causing them to cease operations following the court-authorized action. The distributed architecture of the QTFY infrastructure, which includes QScan, QTRouter, and other components, such as Fast Labyrinth and QTProxy, highlights the complexity and sophistication of the Chinese state-sponsored hacking group's operations.

    The FBI's announcement also underscores the agency's commitment to protecting the nation's critical infrastructure from cyber threats. The disruption of QScan and QTRouter platforms demonstrates the FBI's ability to track and disrupt the activities of sophisticated Chinese state-sponsored hackers, highlighting the importance of international cooperation and information sharing in combating cyber espionage.

    Furthermore, the FBI's announcement highlights the need for increased awareness and education among U.S. organizations about the risks posed by Chinese state-sponsored hacking. The use of QScan and QTRouter platforms by QTFY demonstrates the threat posed by Chinese cyber espionage to U.S. critical infrastructure and national security, emphasizing the importance of robust security measures and incident response planning.

    In conclusion, the FBI's disruption of QScan and QTRouter platforms marks a significant development in the ongoing efforts to combat cyber espionage and protect the nation's critical infrastructure from unauthorized access. The use of these platforms by QTFY highlights the threat posed by Chinese state-sponsored hacking to U.S. critical infrastructure and national security, emphasizing the need for increased awareness and education among U.S. organizations about the risks posed by Chinese cyber espionage.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/FBI-Disrupts-Chinese-State-Sponsored-Hackers-Global-Infrastructure-for-Stealing-US-Data-ehn.shtml

  • https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html


  • Published: Wed Aug 26 16:43:52 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us