
US disrupts Chinese proxy hacking botnet targeting NASA, Senate, and federal agencies
Federal authorities took down two proxy networks used by Chinese intelligence contractor Nanjing Xinjiuwei to breach government departments, energy laboratories, and critical infrastructure.
Infrastructure takedown
The United States Department of Justice announced on 26 August 2026 that federal authorities seized domains used by two Chinese hacking platforms, QScan and QTRouter. Court documents identify the operator as QTFY, a hacking unit managed by the Chinese contractor Nanjing Xinjiuwei Network Technology Company. The firm provided offensive digital services to Chinese state entities, including the Ministry of State Security and the People's Liberation Army. Investigators stated that the infrastructure had been used since at least 2018 to penetrate government networks and critical infrastructure in the United States and abroad. Attorney General Todd Blanche outlined the federal enforcement response following the operation.
State-sponsored hackers targeting America's critical infrastructure will be stopped and held accountable. We are here to keep Americans safe and will use every available tool to deliver on that promise.
Breached agencies and critical sectors
Court filings detail intrusions across multiple federal bodies and private corporations. In August 2019, operators attempted to breach NASA systems, while an intrusion of limited scope affected the Federal Reserve that same year. In September 2024, the campaign breached networks at three Department of Energy laboratories, the Department of Health and Human Services, the National Institutes of Health, and an American security-device manufacturer. Court affidavits show that the United States Senate experienced system compromises as recently as 2026. The targeted list also includes four unnamed companies across the United States and South Korea, alongside power utilities, telecommunications providers, defense contractors, and hospitals.
- Nanjing Xinjiuwei begins offering proxy and hacking services to Chinese state agencies
- Hackers target NASA networks and conduct a limited-scope breach at the Federal Reserve
- Breaches compromise three Department of Energy laboratories, HHS, and NIH
- Hacking group compromises computer systems at the US Senate
- US Department of Justice seizes hardcoded domains, disabling QScan and QTRouter
Proxy routing and detection evasion
The seized infrastructure relied on a two-tier network architecture designed to disguise malicious activity. QScan scanned the internet to identify and compromise thousands of internet-of-things devices, such as routers and network hardware. These infected devices were then consolidated into a proxy network via QTRouter, allowing foreign operators to route attack traffic through civilian hardware located near target organizations. Because domain names were hardcoded directly into the botnet software, the court-authorized domain seizures severed command-and-control communications, rendering the proxy network inoperable. Richard Hummel, a vice president at cybersecurity firm SecurityScorecard, explained the defensive challenges created by localized proxy routing.
When an intrusion appears to come from a device down the street from the target instead of from overseas, it buys the operator time and makes attribution slow. Taking two platforms of that size offline costs the operators real capability they were using every day.
Contractor ecosystem in cyber operations
The operation involved assistance from private threat intelligence teams, including Lumen Technology's Black Lotus Labs, which tracked the group's targeting of defense, aerospace, and government entities over the past year. Analysts describe Nanjing Xinjiuwei as a contractor providing ready-made botnets and relay infrastructure to Chinese intelligence agencies. Chinese diplomatic representatives in Washington did not respond to requests for comment regarding the indictment, and Beijing has consistently rejected accusations of state-directed cyberattacks. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, noted the wider expansion of private hacking vendors supporting state intelligence apparatuses.
In the past decade, the number of companies offering offensive niche services has grown exponentially.

