FBI Seizes Hacking Tools China Used on NASA, the Fed and the US Senate for 8 Straight Years
A Nanjing-based outfit sold its intrusion tools to Beijing's spy service and the People's Liberation Army — until federal agents pulled the plug on both platforms this week.

The Justice Department and FBI have seized the domains behind two hacking tools that a Chinese state-linked group used to breach American government networks for nearly eight years, according to court documents unsealed this week and reported by Help Net Security.
The tools, known as QScan and QTRouter, were built and operated by a group investigators call QTFY, which court filings tie to a company based in Nanjing, China. According to the Justice Department, QTFY sold access to its hacking infrastructure to paying customers that included China's Ministry of State Security and the People's Liberation Army.
Eight Years, Dozens of Agencies
Prosecutors say the intrusion campaign ran from at least May 2018 through June 2026, and that victims included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate, per Nextgov/FCW. In the operation's final month, investigators say QTFY actors even scanned a U.S. election system, though the attempt did not succeed in breaching election networks.
THE SEIZURE RENDERED BOTH TOOLS INOPERABLE WORLDWIDE.
By seizing the domains that QScan and QTRouter depended on to function, the FBI says it has effectively disabled the platforms everywhere they were deployed — not just against U.S. targets — cutting off a tool set that had reportedly been rented out as a hacking-for-hire service to other paying clients as well, according to The Washington Times.
Cybersecurity researchers have described QTFY's business model as emblematic of a growing "hackers for hire" ecosystem in China, where private firms with loose ties to the state build and lease offensive tools rather than government hackers building everything in-house — a structure that officials say makes it harder to trace attacks back to Beijing and easier for the government to maintain deniability.
The Justice Department has not announced criminal charges against specific individuals tied to QTFY, and it remains unclear whether any of the group's operators are outside China's reach for prosecution. Officials say the investigation, which involved multiple federal agencies over several years, remains ongoing.