U.S. law enforcement has dealt another blow to state-sponsored cybercriminals from China. In a joint operation by the U.S. Department of Justice and the FBI, the domains of two key platforms — QScan and QTRouter — were seized. These were used by Chinese government-linked hackers to attack critical infrastructure, including NASA, the Federal Reserve, and the U.S. Senate.

Exposing a Chinese State Contractor

According to court documents, the group behind these platforms is QTFY, affiliated with Nanjing Xinjiuwei Network Technology. This is not merely a case of private malicious actors: QTFY provided hacking services for a fee, with its primary clients being China's Ministry of State Security and the People's Liberation Army. This directly points to the state-sponsored nature of the cyberattacks.

In an official statement, the FBI confirmed that the group's victims included not only NASA and the Federal Reserve, but also the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The scale is striking: the attacks affected the highest echelons of American power and the scientific and technological elite.

How QScan and QTRouter Worked

The mechanics of the attacks were meticulously planned. Hackers used QScan to scan the Internet of Things (IoT) for vulnerable devices, which were then automatically infected. Each such device became part of the QTRouter network — a powerful tool that connected them to commercial proxy services and rented virtual servers.

This created a multi-layered anonymity network: the attacks appeared to originate from various countries around the world, rather than from China. Investigators determined that the seized domains were hardcoded into the code of both tools — they handled both communication and access verification. After the domain seizure, QScan and QTRouter simply ceased to function, confirming the operation's effectiveness.

"Federal agents investigated and blocked malware from China. This is one of the latest operations to technically dismantle reckless attacks supported by the Chinese government," said Attorney General Todd Blanche.

This is not the FBI's first such operation. In 2025, they removed the PlugX virus from more than 4,000 American computers; in 2024, they disabled the Flax Typhoon botnet; and in 2023, they took down Volt Typhoon's infrastructure. The trend is clear: the fight against Chinese cyberespionage is entering a systematic phase.

The number of incidents is growing. Analysts at Taiwan's TeamT5 reported this week that Chinese state-linked groups have doubled the number of attacks after delegating routine work to artificial intelligence models. The case is being handled by prosecutors from the Southern District of California, and they may file charges — which would reveal whether the DOJ is prepared to go beyond simply shutting down servers.

My take: Seizing infrastructure is a strong tactical move, but nothing more. State-sponsored hackers adapt quickly, and the use of AI only accelerates their operations. The crypto community should closely monitor this escalation: cyberattacks on financial regulators and government institutions directly impact trust in digital assets and could trigger new waves of regulation.