
US disrupts Chinese proxy hacking network targeting NASA, Federal Reserve, and Senate
The US Department of Justice seized domains for QScan and QTRouter, two platforms operated by Chinese contractor Nanjing Xinjiuwei to breach federal agencies and critical infrastructure.
Federal takedown of proxy infrastructure
The United States Department of Justice and the Federal Bureau of Investigation seized the internet domains powering two hacking platforms, QScan and QTRouter, which federal prosecutors say were used by Chinese state-sponsored actors to target American government agencies and critical infrastructure. According to court filings and affidavits, the infrastructure was operated by the QTFY group under a Chinese government contractor named Nanjing Xinjiuwei Network Technology Company. The firm provided hacking and proxy relay services to clients including the Ministry of State Security, China's civilian intelligence service, and the People's Liberation Army. US officials stated that the domain seizures rendered both hacking platforms inoperative. Attorney General Todd Blanche characterized the action as part of ongoing federal enforcement against foreign intrusions.
State-sponsored hackers targeting America's critical infrastructure will be stopped and brought to justice. We are here to keep Americans safe and will use every tool available to deliver on that promise.
Scope of government and sector breaches
Court documents reveal that the proxy tools facilitated cyber intrusions and reconnaissance campaigns dating back to at least 2018. Targeted federal entities include the National Aeronautics and Space Administration, the Federal Reserve, the Department of Justice, the US Senate, the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health. Hackers made an unsuccessful attempt to access NASA networks in August 2019, while a breach of limited scope occurred at the Federal Reserve in 2019. In September 2024, hackers successfully breached networks at three Department of Energy laboratories, the NIH, the HHS, and an American security-device manufacturer. The campaign also reached into critical civilian sectors, targeting power companies, telecommunications providers, hospitals, financial institutions, defense contractors, and four unnamed companies in the United States and South Korea.
- Chinese contractor Nanjing Xinjiuwei begins operating QScan and QTRouter platforms
- Hackers launch an unsuccessful attempt to breach NASA networks
- Intrusions breach three Department of Energy laboratories, NIH, and HHS
- US Justice Department and FBI seize domains powering QScan and QTRouter
- Chinese Foreign Ministry rejects allegations and calls claims politically motivated
Technical mechanics of the proxy network
The disrupted tools functioned together to obscure the geographic origin of cyber intrusions. The QScan platform identified and compromised thousands of internet-connected devices, such as commercial routers and Internet-of-Things hardware. These compromised systems were then aggregated through QTRouter into a distributed proxy botnet. By routing attack traffic through intermediaries in third countries or local devices near the victims, operators disguised connections to make them look domestic rather than originating from China. Cybersecurity researchers from Lumen Technology's Black Lotus Labs and SecurityScorecard assisted federal authorities in the technical analysis.
When an intrusion appears to come from a device down the street from the target instead of from overseas, it buys the operator time and makes attribution slow.
Beijing denial and diplomatic friction
The Chinese government rejected the allegations on Thursday, stating that the claims lacked evidence. Chinese Foreign Ministry spokesperson Lin Jian voiced strong opposition during a press briefing in Beijing, accusing Washington of abusing legal enforcement for political purposes and calling the United States the largest source of hacking and espionage globally. Lin cited prior Chinese reports concerning alleged National Security Agency operations against China's National Time Service Center to argue that Washington conducts cyber sabotage against foreign infrastructure. The domain seizures follow previous accusations involving groups like Volt Typhoon and Salt Typhoon, which targeted US infrastructure and political candidates. Chinese President Xi Jinping is scheduled to visit Washington in September 2026.


