Breaking
ESTreasure of Villena, one of Europe's most valuable Bronze Age collections, is stolenTRŞampiyonlar Ligi 2026-2027 sezonu kura çekimi torbaları belli olduFRJudicial news and local incidents: Caen and Saint-DenisCRYPTO-FRNvidia acquires Hugging Face for $12.9 billionDESturzflut an der Grenze zwischen Nepal und China fordert mindestens 160 TodesopferAUFire at Pakistan hospital kills 14 infantsFRNetflix to air exclusive preview of GTA 6CN尼泊爾與中國邊境山區發生大規模山崩與洪災,至少165人喪生ESJabaroot hacker group leaks data of 70,000 Moroccan security agentsESScientists warn of risk of natural dams after flood in the HimalayasESTreasure of Villena, one of Europe's most valuable Bronze Age collections, is stolenTRŞampiyonlar Ligi 2026-2027 sezonu kura çekimi torbaları belli olduFRJudicial news and local incidents: Caen and Saint-DenisCRYPTO-FRNvidia acquires Hugging Face for $12.9 billionDESturzflut an der Grenze zwischen Nepal und China fordert mindestens 160 TodesopferAUFire at Pakistan hospital kills 14 infantsFRNetflix to air exclusive preview of GTA 6CN尼泊爾與中國邊境山區發生大規模山崩與洪災,至少165人喪生ESJabaroot hacker group leaks data of 70,000 Moroccan security agentsESScientists warn of risk of natural dams after flood in the Himalayas
NewsgatherNewsgather
All StoriesWorldSportsFinanceTechScience
Sign In
All StoriesWorldSportsFinanceTechScienceHealthCultureClimatePoliticsSpace
NewsgatherNewsgather

Real-time global news intelligence. Curated by humans, powered by data.

Sections

All StoriesWorldSportsFinanceTechScience

More

HealthCultureClimatePoliticsSpace

Company

AboutEditorial StandardsAdvertisingCareersPressContact

©️ 2026 Newsgather. A product by All Software 24. All rights reserved.

Privacy PolicyCookie PolicyImprintTerms of UseContent and Editorial PolicyRemoval RequestAdvertising PolicyContact
Back|FBI Disrupts Chinese Proxy Network Used for Cyber Espionage Against US Institutions
FBI Disrupts Chinese Proxy Network Used for Cyber Espionage Against US Institutions
NEWS
Wired·3 hours ago·Defense·4 min read

FBI Disrupts Chinese Proxy Network Used for Cyber Espionage Against US Institutions

The DOJ dismantled tools linked to a Chinese contractor that allegedly facilitated state-sponsored hacking of NASA, the US Senate, and critical infrastructure.

Quick Look

  • The FBI and DOJ have disrupted a Chinese proxy network, QTRouter and QScan, used by the group QTFY to infiltrate US government agencies and critical infrastructure.
  • The operation targeted a Nanjing-based contractor linked to China's Ministry of State Security.

AI-generated summary

Why It Matters

The DOJ and FBI disrupted the QTRouter and QScan tools used by the Chinese hacking group QTFY. These tools leveraged IoT botnets and commercial proxies to facilitate espionage against US government and infrastructure targets.

Font size

For years, China's military and intelligence agencies, which carry out hacking campaigns against targets around the globe, have grown increasingly reliant on a vast web of proxy devices that enable and obfuscate their targeting. Now the FBI has named and disrupted one key network of those proxies—and in doing so, revealed just how extensively the hackers who used it reached into American government institutions and US critical infrastructure.

On Wednesday, the Department of Justice announced the takedown of two tools, known as QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY, which is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company. According to prosecutors and an FBI affidavit used to seize domains that those tools relied on, the company gave its customers access to botnets of hacked internet-of-things (IoT) devices and co-opted commercial proxy services. The company's customers—allegedly including the Ministry of State Security and the People's Liberation Army—then used those proxy services as relay points to carry out hacking campaigns stretching back as early as 2018, according to the US government.

The DOJ says the hackers breached a staggering list of US victim agencies, including NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself.

Nanjing Xinjiuwei Network Technology Company could not be immediately reached for comment.

The FBI's affidavit goes on to list types of US infrastructure and industries targeted via the proxy networks, too, including power companies, telecommunications providers, hospitals, financial institutions, and defense contractors—though it does not confirm which of the targeted entities were successfully breached or to what degree.

“The scale is really giant,” says Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, which worked with the FBI and DOJ on the takedown operation. In a blog post about the operation, Black Lotus Labs describes the Nanjing-based company as a kind of “quartermaster” for China's hacking operations, one of several private contractors that increasingly provide key tools and infrastructure to China's state-sponsored hackers.

“This is a very long-lasting campaign,” Rouse says, “and this company and these people involved in it have very close ties to the highest levels of the People's Liberation Army.”

QScan, according to Lumen and the FBI, was designed to scan for vulnerabilities in IoT devices that could be hacked and added to botnets of infected devices that served as proxies. The company's QTRouter service allegedly managed customers’ access to that botnet network, as well as a network of commercial proxies known as virtual private servers that could simply be rented and used in hacking campaigns.

Over the past year, Rouse notes, the group had transitioned to hijacking virtual private network (VPN) services typically used by Chinese citizens to route around China's Great Firewall censorship system. Proxying Chinese hacking operations through those VPNs, Rouse says, created a layer of obfuscation that mixed malicious traffic with the benign traffic of Chinese users seeking to access the open internet. “It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were co-opting,” Rouse says.

The FBI and Justice Department say they've now disrupted the group's proxy infrastructure by seizing key domains hardcoded into QScan and QTRouter. Lumen, which serves as an internet backbone provider, says it also “null-routed” certain domains, rendering them inoperable—including the more recent system of co-opting censorship-bypassing VPNs.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” US attorney general Todd Blanche wrote in a statement, though the DOJ's announcement didn't appear to include charges against any individuals. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”

Exactly what the QTFY hackers or the group's clients within the Chinese government sought to accomplish with its US infrastructure hacking is far from clear. Rouse says that the hacking campaigns don't appear to overlap with China's Volt Typhoon hacking campaign, which has sought to gain the capability to disrupt US power, water, and other military and civilian infrastructure. Instead, he says, the years-long hacking operations appeared—at least within Lumen's visibility—to be focused on more traditional espionage. “It was pretty much as broad as you can get, mapping back to what Chinese cyber operations are tasked with in terms of information collection,” Rouse says.

The disruption of the QTFY proxy network will create a setback for those hacking campaigns and some embarrassment and customer relations problems for the Nanjing Xinjiuwei Network Technology Company, Rouse says. But given the hackers’ flexibility in shifting their methods over the years to find new ways to relay and disguise malicious traffic, he has no doubt that they will adapt and return.

“I think this will have a direct effect on the company and its perception in China. This is an egg-on-the-face moment for them,” Rouse says. “I think we can also safely assume they'll pivot and stand up new infrastructure.”

What to Watch

AI outlook — possibilities, not facts

  • The hacking group will pivot to new infrastructure and methods.

    Very likely · Within months

Open Questions

  • ?Which specific entities were successfully breached?
  • ?Will there be formal indictments against individuals?

Related Topics

People
Organizations
Places
Topics
This article was originally published by Wired.

Quick Look

  • The FBI and DOJ have disrupted a Chinese proxy network, QTRouter and QScan, used by the group QTFY to infiltrate US government agencies and critical infrastructure.
  • The operation targeted a Nanjing-based contractor linked to China's Ministry of State Security.

AI-generated summary

Story signals

News tone
Negative
Emotional intensity
High
News value
High
Global impact
Global
Follow-up likelihood
Likely
Relevance window
Weeks

Source & Reliability

Source
Wired
Story type
Hard news
Source quality
Full
Published
3 hours ago
Last updated
3 hours ago

Related Stories

More on this topic
US Army to award $2.2 billion for micro-nuclear reactors on military bases
Defense·2 hours ago

US Army to award $2.2 billion for micro-nuclear reactors on military bases

The US Army is awarding $2.2 billion in contracts to five companies to develop portable microreactors for military installations. The initiative seeks to ensure energy independence for combat power, though critics argue the program acts as a costly subsidy.

Deutsche Welle
3 min read
Ukrainian airstrike kills nine in Luhansk; Kyiv targets Russian logistics
BREAKING·3 hours ago

Ukrainian airstrike kills nine in Luhansk; Kyiv targets Russian logistics

A Ukrainian airstrike in the Russian-occupied Luhansk region killed nine people, according to local occupation leader Leonid Pasechnik. Simultaneously, Ukrainian drone strikes destroyed a major Wildberries warehouse in Russia's Tambov region.

Deutsche Welle
1 min read
Zelenskyy Appoints New Commanders for Donetsk Defense as Conflict Intensifies
Urgent·8 hours ago

Zelenskyy Appoints New Commanders for Donetsk Defense as Conflict Intensifies

President Zelenskyy has appointed commanders Andrii Biletskyi and Denys Prokopenko to lead defense efforts in Donetsk. Meanwhile, Ukraine continues long-range drone strikes on Russian infrastructure, while Russia intensifies ballistic missile attacks on Ukrainian cities.

Guardian International
3 min read
US military strike kills four in Caribbean Sea
Developing·23 hours ago

US military strike kills four in Caribbean Sea

The US military killed four people in a Caribbean Sea strike, claiming the vessel was involved in drug trafficking. The operation is part of a yearlong campaign against Latin American cartels that has drawn significant criticism from international human rights groups.

Deutsche Welle
2 min read
Security concerns mount as third drone found near Leipzig/Halle Airport
Developing·yesterday

Security concerns mount as third drone found near Leipzig/Halle Airport

A third drone, potentially carrying Hexogen explosives, was discovered near Leipzig/Halle Airport. The incident has intensified debates over Germany's drone defense capabilities, jurisdictional fragmentation, and the threat of hybrid attacks.

Deutsche Welle
4 min read
UN and Red Cross Urge Ban on Autonomous Weapons Systems Amid 'Intensified Risks'
Defense·yesterday

UN and Red Cross Urge Ban on Autonomous Weapons Systems Amid 'Intensified Risks'

The UN and ICRC intensified their joint appeal for countries to ban or restrict autonomous weapons systems, warning of 'intensified risks' as military technology outpaces regulation, ahead of a key Geneva conference in November.

The Independent World
2 min read
More on this topic
cybersecurity
espionage
fbi
cybersecurity
Damon Rouse
Todd Blanche
FBI
Department of Justice
Nanjing Xinjiuwei Network Technology Company
Lumen Technology
Nanjing
China
United States
espionage
fbi
china
iot
nanjing xinjiuwei
cybersecurity
cybersecurity