FBI Disrupts China-Linked QTFY Hackers After Infiltrating U.S. Networks
The FBI and Department of Justice seized three internet domains tied to China-linked hacking group QTFY on Wednesday, August 26, 2026, crippling its QScan scanning and QTRouter anonymization platforms.[1]
Newly unsealed court records say QTFY stole data from more than 300 victim organizations, including U.S. defense contractors, financial firms and universities.[1] The FBI affidavit says QTFY successfully breached three Department of Energy laboratories, the National Institutes of Health and a Department of Health and Human Services agency before the takedown.[1] Federal advisory documents cited in filings say QTFY scanned Senate and hospital networks in March 2026 and probed a U.S. election system in June 2026, though those attempts reportedly failed.[1]
The Nanjing Xinjiuwei Network Technology Company was formed in China in 2018 and began operating the QScan platform and QTRouter anonymization network that year. The company employed former People's Liberation Army personnel and sold offensive cyber services to China's Ministry of State Security and to the PLA. The FBI's San Diego field office opened an investigation into the group in 2019 after tracing infrastructure used in an unsuccessful August 2019 Pulse Secure VPN exploit attempt against NASA, the Federal Reserve and Justice Department systems.
Court records show the FBI tracked QTFY activity through at least 2025 before moving to seize the domains. QScan alone processed more than 2 million scanning and penetration-testing tasks on a single day in 2024 and housed over 200 proof-of-concept exploits, details that investigators say helped map the group's scope and targets.[1]
The mainstream summary does not mention the broader context of increasing Chinese cyber intrusions, which reportedly surged by 150 percent across all sectors in 2024 compared to the previous year, particularly affecting financial services, media, and manufacturing. This statistic underscores the escalating threat that groups like QTFY pose, highlighting that the FBI's takedown is part of a larger trend of intensified cyber espionage efforts by China. The Department of Justice's prior actions against other state-sponsored operations, such as the removal of PlugX malware from over 4,000 U.S. computers, further illustrate the ongoing battle against these threats and the need for proactive measures.[2]
While the mainstream account focuses on the specifics of the QTFY operation, it downplays the structural shifts in China's espionage strategy under Xi Jinping, which have prioritized technological and military advancements through cyber means. This strategic pivot has led to the commercialization of cyber operations, with private contractors like QTFY integrating into a broader cyber ecosystem that supports state objectives. This context is vital for understanding the significance of the FBI's actions and the persistent challenges posed by state-sponsored cyber threats.[3] and NCSC provide insights into these evolving dynamics.
Show source details & analysis (1 source)
📊 Relevant Data
The Department of Justice has previously disrupted PRC-sponsored operations including removal of PlugX malware from over 4,000 U.S. computers by Mustang Panda in 2025 and disablement of a botnet with hundreds of thousands of compromised IoT devices operated by Flax Typhoon in 2024.
Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure — United States Department of Justice
China-nexus intrusions increased 150 percent across all sectors on average in 2024 compared to 2023, with increases of 200-300 percent in financial services, media, manufacturing, and industrials sectors.
Hearing before the U.S. House Committee — Congress.gov
📌 Key Facts
- Newly unsealed court records state QTFY stole data from more than 300 victim organizations, including U.S. defense contractors, financial firms and universities.
- The FBI affidavit says QTFY successfully breached three Department of Energy laboratories, NIH and a Department of Health and Human Services agency before the takedown.
- On Wednesday, August 26, 2026, the FBI and DOJ seized three domains supporting QTFY’s QScan and QTRouter platforms, which officials say crippled the group’s operations.
- QScan processed more than 2 million scanning and penetration-testing tasks on a single day in 2024 and housed over 200 proof-of-concept exploits.
- Federal advisory documents cited in the article say QTFY recently scanned Senate and hospital networks in March 2026 and a U.S. election system in June 2026, though those attempts reportedly failed.
📰 Source Timeline (1)
Follow how coverage of this story developed over time