DOJ Dismantles Chinese Proxy Network QTRouter/QScan Behind Attacks on US Agencies
The Justice Department seized domains tied to two tools, QTRouter and QScan, that a Chinese hacking group called QTFY used to route attacks through hijacked IoT devices and commercial proxy services. Prosecutors say the network, allegedly linked to Nanjing Xinjiuwei Network Technology Company and used by China's Ministry of State Security and PLA, enabled breaches at NASA, the Senate, the Federal Reserve, HHS, NIH, and the DOJ itself since at least 2018.
GoKawiil's interpretation of the reporting above, not reported fact.
This takedown exposes how deeply Chinese state hackers have embedded themselves in ordinary internet infrastructure to mask espionage operations against core US government functions and critical sectors like energy, telecom, and finance. It signals that proxy-based obfuscation, not just direct intrusion, has become a central pillar of state-sponsored cyber campaigns that US law enforcement is now trying to systematically unravel.
- The FBI seized domains behind Chinese-linked proxy tools QTRouter and QScan.
- Breached targets reportedly include NASA, the Senate, the Federal Reserve, and the DOJ.
- The proxy network also targeted power, telecom, healthcare, and defense sectors since 2018.
Firewalla Purple Smart Firewall — Since these campaigns hijack home routers and IoT gadgets as proxy relays, a network-level firewall like Firewalla Purple lets you see exactly what every device on your network is talking to and block suspicious outbound connections. It plugs into your existing router setup and gives you intrusion detection, device-level rules, and alerts from a phone app. A practical step toward making sure your smart plugs and cameras aren't quietly working for someone else.
See Firewalla Purple Smart Firewall on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: wired.com — Andy Greenberg, 2026-08-26
Published there as: “FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.