Skip to content
South China Morning Post
The Justice Department and the FBI said on Wednesday that they seized two Chinese state-sponsored online platforms that targeted US critical infrastructure and other critical networks, including Nasa, the Federal Reserve and the US Senate.
According to court documents, the seizures involved a group known as "QTFY", operated by China-based Nanjing Xinjiuwei Network Technology Co, which created and ran the QScan and QTRouter sites.
"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," said US Attorney General Todd Blanche in a statement. "Federal law enforcement investigated and disabled [China's] malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China [PRC]."
QTFY allegedly offered computer hacking services for a fee to its clients, including China's Ministry of State Security (MSS) and the People's Liberation Army, according to court documents in the Southern District of California.
The Chinese embassy in Washington said the Chinese government opposes and combats all forms of cyberattacks. "We urge the US side to stop using cybersecurity issues to smear or discredit China," the spokesman said.
Other reported victims of the QTFY hacking operations included the Department of Energy, Department of Justice, Department of Health and Human Services and the National Institutes of Health as well as hospitals, telecommunications providers, power companies, financial institutions and defence contractors.
"We're taking the fight to PRC-sponsored cybercriminals to protect the critical services Americans rely on every day," said US Attorney Adam Gordon for the Southern District of California.
In reality, however, the transnational nature of threats, the relative anonymity of foreign individuals involved and the ease in creating and moving sites make it difficult to prosecute and otherwise counter cyberhacking operations, analysts said.
Another concern: the Trump administration has cut staff and budgets significantly at US agencies responsible for fighting these threats, including the Federal Bureau of Investigation, National Security Agency (NSA), Federal Communications Commission and Cybersecurity and Infrastructure Security Agency, or CISA.
"The CISA workforce has been cut by nearly a third, and the scope of the agency has been reduced, leaving the US more exposed to adversarial cyber threat actors," said the Washington-based non-partisan New Lines Institute in an October 2025 report. "National cybersecurity infrastructure cannot become a casualty to partisanship."
As outlined by the Justice Department on Wednesday, QTFY's hacking services, such as QScan and QTRouter, tended to work in tandem. QScan would scan and automatically infect thousands of smart devices worldwide – such as video doorbells, fitness trackers and heart rate monitors – that were then added to the QTRouter network of devices it controlled.
QTRouter, in turn, would operate as an "obfuscation network". That allowed QTFY and other "malicious cyber actors" to conceal the Chinese origin of their activities by making communications appear to originate from computers outside China, the agency said.
QTFY's malicious cyber activities dated back to at least 2018, according to an FBI affidavit, which said QTFY, also known as QT and QTCYBER, tended to hire former PLA employees who used their connections to gain business and sign contracts.
The move to seize and make inoperable QScan and QTRouter was justified, the court said, given that money-laundering laws were violated to pay for the US sites and because the seized domains were hard-coded into both the QScan and QTRouter malware, which were used for such essential tasks as communication and authentication.
China has frequently denied accusations of state-sponsored cyber hacking, rejecting them as "unfounded" and "a smear".
Western intelligence agencies and cybersecurity firms, including Microsoft, Mandiant and CrowdStrike, have identified a number of Chinese state-backed threats, however, including Volt Typhoon, reportedly sponsored by the People's Liberation Army Cyberspace Force and Salt Typhoon allegedly sponsored by MSS.
In its 2025 report, New Lines said Salt Typhoon was in US telecoms networks at least since 2023 and possibly as far back as 2019.
"One of the most troubling and unique elements of the Salt Typhoon campaign is that its persistence model relied on having access to the supply chain on the most fundamental level," the group said. "Given enough time, this access provides the group with data on just about any person or entity residing in the US that it seeks to target. Data has been exfiltrated on over 1 million users, including senior US officials."
"The MSS has been known to outsource to an extensive network of private companies and contractors to conduct cyber operations," New Lines added. "This type of structure allows the Chinese government to obfuscate its involvement."
US President Donald Trump appeared to defend China's cyber hacking activities. "You don't think we do that to them? We do," he told Fox in June. "That's the way the world works. It's a nasty world."
But analysts pushed back.
"Critical differences exist between what we and they do. US government computer network operations seek a clearer picture of foreign capabilities and intent. That is, a form of intelligence collection," said William Hannas, a lead security analyst at Georgetown University and former CIA official.
"Chinese hacking, directly or through its proxy networks, besides intelligence gathering, aims to gain commercial advantages, exfiltrate proprietary technology, gain leverage over institutions and individuals," he added.
In a related development, Trump on Wednesday signed an emergency order keeping some foreign-made transformers and other critical energy equipment out of the nation's electric grids on national security grounds.
In signing the order, Trump warned of "certain foreign actors" who are "increasingly creating and exploiting vulnerabilities in the United States bulk-power system" without mentioning China by name.