The US Department of Justice and the FBI announced the seizure of two hacking platforms tied to a Chinese state-sponsored cyber group that allegedly breached some of the most sensitive institutions in the country, including the Federal Reserve.

The platforms, known as QScan and QTRouter, were attributed to a group called QTFY, which the US government linked to the Nanjing Xinjiuwei Network Technology Company. The tools reportedly allowed hackers to mask their origins while penetrating targets across the federal government and critical infrastructure sectors.

What was breached and how it worked

The list of named victims includes the Federal Reserve, NASA, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The affected targets also spanned critical infrastructure sectors including telecommunications providers, hospitals, and financial institutions.

QScan and QTRouter functioned as obfuscation tools, letting attackers route their intrusions through layers of misdirection so that tracing the source became exponentially harder.