The US government has disrupted a sprawling state-sponsored Chinese hacking operation responsible for breaching the networks of top government agencies, the Justice Department said Wednesday - including its own network.
The Justice Department said in a statement that it had seized two domains used by the Chinese hackers - dubbed 'QScan' and 'QTRouter' - to target US critical infrastructure and other sensitive networks within the federal government.
The Chinese-linked hackers breached the networks of the Federal Reserve, NASA, and the US Senate, among others, federal prosecutors said Wednesday.
The Department of Energy, the Department of Health and Human Services, and the National Institutes of Health were also victimized by the group, prosecutors said, as well as four unnamed companies in the US and South Korea.
'Other targeted networks include those operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors,’ DOJ officials said in a court filing.
The hacking platforms were run by a Chinese state-sponsored group, 'QTFY,' according to an affidavit DOJ filed in federal court - and whose paying customers include China's civilian intelligence agency, its Ministry of State Security, and China's People’s Liberation Army.
Federal prosecutors said the PRC-aligned group had been working to breach US critical infrastructure and sensitive federal agencies since at least 2018 - underscoring the long-running nature of these state-sponsored hacking operations, and the increasingly sophisticated ways by which hackers are gaining access to the networks in question, and almost immediately concealing their origin.
Attorney General Todd Blanche and FBI Director Kash Patel speak to reporters in Washington, DC
President Donald Trump greets Chinese President Xi Jinping ahead of a bilateral meeting. Xi Jinping is slated to travel to Washington, DC, to meet with Trump in September
The J. Edgar Hoover Federal Bureau of Investigation building and the US Department of Justice building are seen in Washington, DC
QScan, for example, offered customers the ability to scan for and 'automatically infect' thousands of IoT, or internet-of-things devices. IoT devices, in layman's terms, include any appliance or device that hooks up to the internet, such as smart TVs, internet-linked speakers, or even security cameras and smart refrigerators.
From there, QScan would add the infected devices to the QTRouter, which served as an obfuscation network - allowing the Chinese-linked firm QTFY and other malicious hackers to cover their tracks and their origin from within the People's Republic of China.
'State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,' Attorney General Todd Blanche said in a press release announcing the disruption.
'Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.'
The news comes as President Donald Trump and Chinese President Xi Jinping are slated to have another bilateral meeting in DC this September, following the Trump's trip to China in May.
And it comes as the DOJ and FBI have worked in concert for years to crack down on state-sponsored hacking operations, including sophisticated operations with ties to Russia or China.
'The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure,' said Special Agent in Charge Mark Remily of the FBI San Diego Field Office.
'Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries. We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.'









