
Federal agents in San Diego seized three internet domains this week that powered a sprawling Chinese state-sponsored hacking network blamed for breaching NASA, the Federal Reserve, the Department of Justice and the U.S. Senate. The domains — qtproxy.xyz, qt-proxy.org and qt-team.com — served as the command backbone for two linked hacking platforms known as QScan and QTRouter, according to newly unsealed federal court documents.
The court-authorized seizure, announced by FBI San Diego, targeted infrastructure used by a hacking group tracked as QTFY. Court filings unsealed by the U.S. Attorney's Office for the Southern District of California describe QScan as a tool that scanned the internet for network vulnerabilities, while QTRouter obfuscated the origin of attacks by routing traffic through compromised devices. According to the same filings, QTFY's infrastructure had been targeting critical networks in the U.S. and abroad since at least 2018.
In its own post announcing the operation, FBI San Diego said the disrupted platforms were built on networks that infected everyday devices worldwide before being turned against American targets. The bureau said QTFY's tools were used to attack telecom providers, hospitals, power companies, defense contractors, financial institutions, universities and government agencies both in the United States and abroad, and that the seizures cut off the group's ability to conduct future attacks using that specific infrastructure.
A Chinese Contractor With Military Ties
Unsealed records identify Nanjing Xinjiuwei Network Technology Company, a private Chinese firm, as the contractor operating QTFY under funding from China's Ministry of State Security, according to the U.S. Attorney's Office for the Southern District of California. An FBI affidavit unsealed in federal court further found that QTFY's operational personnel included former members of China's People's Liberation Army, who the affidavit says leveraged military connections to secure government cyber contracts and subcontracts, as reported by TeleTrader.
Court filings describe how QScan automatically scanned and infected thousands of Internet of Things devices around the world, funneling them into QTRouter's network of hijacked hardware, commercial proxies and virtual private servers, per cnBeta's account of the unsealed documents. That botnet of everyday consumer devices allowed the hackers to mask where their intrusions were actually coming from. Investigators also traced domain registration records for the seized infrastructure to Chinese phone numbers, street addresses, bank cards and payment platforms including Alipay, according to PowerGame.
Federal Response and Prosecutorial Leadership
The domain seizure warrants were pursued by U.S. Attorney Adam Gordon for the Southern District of California alongside Assistant Attorney General John A. Eisenberg of the Justice Department's National Security Division, according to court documents cited by Diario Bitcoin. Alongside the seizures, the FBI and NSA issued a joint cybersecurity advisory containing technical indicators of compromise, while Lumen Technologies' Black Lotus Labs published its own independent analysis of QTFY's tactics, techniques and procedures, per the U.S. Attorney's Office.
Special Agent in Charge Mark Remily of the FBI's San Diego Field Office framed the takedown as part of a sustained campaign against foreign cyber adversaries. “The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure,” Remily said. “Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries.”
“We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity,” Remily added. FBI San Diego described the effort as part of a broader, ongoing bureau initiative to identify, disrupt and impose costs on PRC-sponsored cyber actors who target the American people.
Part of a Broader Pattern of Takedowns
This week's action follows a string of similar U.S. technical disruptions of Chinese state-linked infrastructure, including the 2025 removal of the Mustang Panda group's PlugX malware, the 2024 disruption of a Flax Typhoon botnet, and the 2023 takedown of Volt Typhoon infrastructure, according to cnBeta. Federal officials describe those operations as evidence of a shift from passive network defense toward active seizures aimed squarely at the infrastructure adversaries rely on.
Even so, significant questions remain unresolved. It is unclear whether QTFY's operators maintain backup infrastructure that could allow the group to resume operations, and the full scope of any data exfiltrated from targeted agencies such as the Federal Reserve and NASA has not been disclosed. How Beijing will respond, beyond its standard denials of state-sponsored cyber activity, also remains to be seen.









-4.webp?w=1000&h=1000&fit=crop&crop:edges)