Skip to content

Thursday, August 27, 2026

Gigantum.net
World

US Justice Department and FBI seize domains claimed to be used by China-linked hacking group targeting NASA, Federal Reserve and more

Tech News News: The US Justice Department and the FBI have announced the seizure of internet domains linked to two hacking platforms allegedly used by a China state-s.

· 411 words

The US Justice Department and the FBI have announced the seizure of internet domains linked to two hacking platforms allegedly used by a China state-sponsored cyber group to target critical infrastructure and sensitive networks. The platforms, known as QScan and QTRouter, were allegedly used to hide the origin of cyberattacks by routing malicious activity through compromised devices around the world. US authorities said the group's alleged victims included NASA, the Federal Reserve, the Department of Energy, the Department of Justice and the US Senate.FBI says platforms were used to hide the origin of attacksAccording to court documents, US authorities have linked the platforms to a group known as QTFY, which they say is employed by China-based Nanjing Xinjiuwei Network Technology Company. The Justice Department alleged that the group offered hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army.QScan allegedly scanned and automatically infected thousands of internet-connected devices, adding them to a network controlled through QTRouter.The compromised devices were then used to make malicious internet traffic appear to come from locations outside China, helping hackers conceal the origin of their activities, according to the Justice Department.“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks.”Seized domains made QScan and QTRouter inoperable, DOJ saysThe Justice Department said the seized domains were hard-coded into the QScan and QTRouter malware and were needed for important functions, including communication and authentication. As a result, the court-authorized domain seizures made both platforms inoperable, according to the department.“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”The latest action follows several other operations by US authorities against alleged China-sponsored hacking activity. In 2025, the FBI said it removed PlugX surveillance malware from more than 4,000 computers in the US that had been infected by the group known as Mustang Panda. In 2024, authorities said they disabled a large network of compromised internet-of-things devices linked to Flax Typhoon. The FBI also disrupted another botnet in 2023 that it said was used by Volt Typhoon to conceal cyber activity targeting critical infrastructure.Get the latest technology news and updates. Download the TOI App.

Gathered from external sources. Rights to this text belong to whoever originally published it.