The Federal Bureau of Investigation (FBI) and National Security Agency have disrupted a China-linked hacking operation that targeted U.S. critical infrastructure and sensitive networks.

The agencies announced the action Wednesday, with the Justice Department and FBI saying they seized domains used by QTFY platforms QScan and QTRouter. The NSA, FBI and Cyber National Mission Force also issued a joint cybersecurity advisory on the group’s activity dating back to 2018.

"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," FBI Director Kash Patel said in the Justice Department release. "These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down."

How QTFY Hid Its Attacks

QTFY is linked by U.S. authorities to China-based Nanjing Xinjiuwei Network Technology Company. Investigators say the group used QScan to scan and exploit vulnerable internet-connected devices and QTRouter to conceal the origin of its attacks.