💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Federal authorities have charged that a China-linked hacking operation mounted intrusion attempts against some of America’s most critical networks, according to allegations announced by the Justice Department and FBI on August 26. The campaign targeted NASA, the Federal Reserve, the Justice Department, the U.S. Senate, along with the Department of Energy, Department of Health and Human Services and National Institutes of Health since at least 2018. Four unnamed companies operating in the United States and South Korea were also victimized.
The Justice Department identified the operation as the work of QTFY, a Chinese state-sponsored group that created and operated hacking tools called QScan and QTRouter. Federal prosecutors allege the group worked on behalf of Nanjing Xinjiuwei Network Technology Company, a China-based firm that purportedly provided hacking services to paying customers including the Ministry of State Security and People’s Liberation Army. The infrastructure deployed in these attacks also targeted hospitals, telecommunications providers, financial institutions and defense contractors.
QScan functioned as a reconnaissance platform that scanned for vulnerable internet-of-things devices worldwide and automatically infected thousands of them, according to court documents. QTRouter then served as an obfuscation network, routing malicious communications through compromised IoT devices and commercial proxy servers to disguise the true origin of attacks. This infrastructure allowed attackers to make their activities appear to originate outside China or near the targeted networks themselves, complicating efforts by security teams to track perpetrators.
FBI Director Kash Patel emphasized the sophistication of the concealment strategy. “These tools were used by PRC cyber actors to hide the origin of their attacks,” Patel said in remarks about the operation. The attackers exploited forgotten or abandoned connected devices—routers left unpatched for years, security cameras no longer receiving manufacturer updates—because such equipment typically receives minimal security attention from users.
Federal authorities obtained court authorization to seize domains that were hardcoded into the malware and essential for the hacking platforms to function, including communication and authentication processes. Once the Justice Department took control of these domains, both QScan and QTRouter became inoperable, effectively dismantling the operation’s infrastructure. Researchers at Black Lotus Labs noted that targeting shared infrastructure of this nature can simultaneously degrade the capabilities of multiple threat campaigns relying on the same systems.
NASA declined to discuss specific vulnerabilities or incidents for security reasons but stated in a prepared comment that the agency remains committed to cybersecurity and works closely with federal partners including the Cybersecurity and Infrastructure Security Agency. A spokesperson for the Chinese Embassy in Washington denied the allegations, stating that China opposes all forms of cyberattacks and accused the United States of using cybersecurity issues to discredit Chinese companies.
The operation follows previous federal disruptions of Chinese hacking groups. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the Mustang Panda group. During 2024, federal agents disabled a botnet comprised of hundreds of thousands of compromised IoT devices linked to Flax Typhoon. Earlier interventions also targeted botnets used by Volt Typhoon and the Salt Typhoon campaign, which penetrated major American telecommunications networks.
Security experts recommend that individuals update router firmware regularly, replace aging routers that no longer receive manufacturer support, and change default administrator passwords to strong, unique credentials. Enabling two-factor authentication on router administration accounts, using WPA3 or WPA2 wireless security protocols, and disabling unnecessary features such as remote management and WPS can significantly reduce vulnerability. Separating internet-of-things devices onto dedicated networks, monitoring connected devices for unfamiliar equipment, and keeping operating systems updated across all devices provides additional layers of protection against compromise.
More Stories
Trump Threatens FCC Action Against NBC’s Welker Over Endorsement Coverage
Chicago Mayor Issues Executive Order Requiring Contractor Diversity Disclosures and ICE Ties Reporting
Democratic Candidate Pia Dandiya Discusses House Race in District 22