federal reserve building
The Justice Department and FBI announced that they had seized three internet domains used to operate two hacking platforms, which authorities say were deployed against U.S. critical infrastructure and sensitive government networks. Annabelle Gordon/AFP via Getty Images

Some of the most sensitive institutions in the U.S. government, including the Federal Reserve, NASA, the Department of Justice and the U.S. Senate, were victims of computer intrusions linked to a Chinese state-sponsored hacking operation, federal authorities revealed.

The Justice Department and FBI announced that they had seized three internet domains used to operate two hacking platforms, QScan and QTRouter, which authorities say were deployed against U.S. critical infrastructure and sensitive government networks. The domains were identified in court documents as qtproxy.xyz, qt-proxy.org and qt-team.com.

According to court documents unsealed in the U.S. District Court for the Southern District of California, the platforms were created and operated by a Chinese state-sponsored hacking group known as QTFY. The group was employed by China-based Nanjing Xinjiuwei Network Technology Company.

Among the federal victims identified by the DOJ were NASA, the Federal Reserve, the Justice Department, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate. Authorities said other networks targeted by the operation included hospitals, telecommunications companies, power providers, financial institutions and defense contractors.

The Justice Department did not disclose what information may have been accessed or stolen from the agencies, nor did it detail the extent of any damage caused by the intrusions. "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," Attorney General Todd Blanche said in announcing the operation. "We are here to ensure security for the American people and will use every tool we have to keep that promise."

Federal investigators described QScan and QTRouter as complementary pieces of a sophisticated cyber infrastructure designed both to compromise devices and to conceal where attacks were coming from.

QScan automatically scanned for and infected thousands of internet-connected devices around the world. Those compromised devices could then become part of QTRouter, a network that also incorporated commercial proxy devices and leased virtual private servers.

QTRouter functioned as an "obfuscation network," according to the DOJ, allowing Chinese-linked hackers and their customers to disguise the origin of cyberattacks. Malicious traffic could appear to originate from compromised computers outside China, including devices located close to the networks being targeted.

Authorities said QTFY offered hacking services to paying customers that included China's Ministry of State Security and the People's Liberation Army. The three domains seized by U.S. authorities were hard-coded into the QScan and QTRouter malware and were essential for functions including communications and authentication.

Taking control of the domains rendered both platforms inoperable, according to the Justice Department. FBI Director Kash Patel said the operation had disrupted "a global botnet and hacking platform" used by Chinese state-sponsored actors to target American infrastructure and conceal the source of their attacks.

Wednesday's action is the latest in a series of U.S. operations aimed at dismantling Chinese-linked cyber infrastructure. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers that authorities said had been infected by the China-linked Mustang Panda group.

A year earlier, authorities disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices linked to Flax Typhoon. The FBI also disrupted infrastructure used by the Volt Typhoon hacking group in 2023.

The latest disclosure also comes just weeks after former Federal Reserve senior adviser John Harold Rogers was sentenced to 38 months in prison for making false statements to investigators about sharing restricted information concerning U.S. monetary policy with individuals identified by prosecutors as Chinese intelligence operatives. Rogers was acquitted of the more serious charge of conspiracy to commit economic espionage.