The FBI and Department of Justice pulled the plug on two hacking platforms linked to a Chinese state-sponsored group, seizing three internet domains that served as the backbone for what officials described as a sprawling cyber espionage operation targeting US government networks and critical infrastructure.

The platforms, known as QScan and QTRouter, were allegedly operated by a group called QTFY, which US authorities have tied to employees of Nanjing Xinjiuwei Network Technology Company. By taking control of the domains, authorities effectively rendered both platforms inoperable, since the malware relied on those domains for communication and authentication.

A hacking-as-a-service operation at industrial scale

The scope of the operation was not subtle. In a single day in May 2024, QScan executed over 2 million scanning and exploitation tasks, exploiting a vulnerability in Check Point software to compromise more than 300 US organizations in one sweep.

QTFY allegedly offered hacking-as-a-service to Chinese government entities, including the Ministry of State Security and the People’s Liberation Army. The group used compromised Internet of Things devices and commercial proxy networks to mask its activity, making detection significantly harder for defenders. Their target list includes NASA, the Federal Reserve, the US Senate, and numerous other critical organizations.