Skip to content
TEN Brief Ten verified stories a day 2026.08.28 KO

이 기사는 한국어로도 읽을 수 있습니다 →

World · 3 min read · Breaking

US seizes China state-sponsored hacking platforms (August 26, 2026) — NASA and the Fed were on the victim list

The US Justice Department and FBI said on August 26, 2026 that they had seized, under court authorization, the domains behind two complementary hacking platforms called QScan and QTRouter. The platforms were built and run by a China-based company, Nanjing Xinjiuwei Network Technology, through a state-sponsored group known as QTFY, which sold hacking services to customers including operators working for China's Ministry of State Security. Victims include NASA, the Federal Reserve, and the Departments of Energy, Justice and Health and Human Services. Intrusion activity dates to 2018, and the Senate was targeted as recently as 2026

A tidy rack of network routers and patch panels with neatly bundled colorful cables in a bright, daylit room

The three lines

  • Action — Justice Department and FBI seized the domains behind QScan and QTRouter under court order
  • Actor — QTFY, inside China-based Nanjing Xinjiuwei Network Technology, with Ministry of State Security hackers as customers
  • Victims — NASA, the Federal Reserve, Energy, Justice, HHS, NIH. The Senate was scanned but not breached

Key questions

What exactly did the US seize?
**Domains, not servers or hardware.** The Justice Department and FBI obtained court authorization to seize the domains used by two complementary hacking platforms, **QScan** and **QTRouter**. The Department said the seizures rendered the botnet and its command and control servers **inoperable**, and gave a specific reason: **those domains were hardcoded into the botnet's code**. Infected machines were built to contact that fixed address for instructions, so removing control of the address leaves them with nowhere to check in. This matters because seizing physical servers located in China is not available to a US court — but **taking the address severs the connection** regardless of where the hardware sits.
Who ran it, and why is a private company named?
**Because the state did not operate it directly — a commercial vendor did.** According to the Justice Department, the two platforms were created and operated by **Nanjing Xinjiuwei Network Technology**, a China-based company, through a group known as **QTFY**. QTFY **sold hacking services to customers**, and those customers included **hackers working for China's Ministry of State Security**. The structure inserts a commercial layer between the state and the intrusion. That has two effects: it complicates direct attribution to the government, and it **scales the operation**, because the same tooling can be resold to multiple customers. This publication covered the market for vulnerabilities in "What a zero-day is."
Were these agencies actually breached, or just targeted?
**It differs by agency, and the distinction matters.** The victim list in the court documents includes **NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health**; one outlet also reported hospitals among the targets. Intrusion activity dates back to **2018**. For the **Senate**, however, an NSA advisory stated the hackers **scanned the networks but were unsuccessful in gaining access**. So the Senate was a target, not a confirmed breach. Headlines frequently group it with the others, but **targeted and compromised are different claims**. What data was taken from which agency, and in what volume, does not appear in the public materials.

The US Justice Department and FBI announced on August 26, 2026 that they had seized the domains behind two China-linked hacking platforms.

The platforms: QScan and QTRouter.

On the victim list: NASA and the Federal Reserve.

1. A company, not a ministry

ElementName
CompanyNanjing Xinjiuwei Network Technology (China-based)
GroupQTFY
CustomersHackers working for the Ministry of State Security, among others
PlatformsQScan · QTRouter

The structure has an extra layer. The state did not run the intrusion directly — a commercial vendor built and operated the tooling and sold access.

That arrangement does two things. It complicates direct attribution to the government. And it scales the operation, because the same platform can be resold to multiple customers rather than built once for one client.

The Justice Department said QTFY offered hacking services to its customers, and that those customers included Ministry of State Security operators.

2. The victims

AgencyDomain
NASASpace
Federal ReserveCentral banking
Department of EnergyEnergy, nuclear
Department of JusticeLaw enforcement
HHS · National Institutes of HealthHealth, research
SenateLegislature

Intrusion activity dates back to 2018. The Senate was targeted as recently as 2026.

One distinction has to be preserved here. The Senate was targeted but not breached. An NSA advisory stated the hackers scanned the networks but were unsuccessful in gaining access.

Headlines routinely group the Senate with the confirmed victims. Targeted and compromised are different claims.

3. Why taking a domain stops a botnet

The seizure covered domains, not machines. A US court cannot seize hardware sitting in China.

Yet the Justice Department said the action rendered the botnet and its command and control servers inoperable. The reason:

StepWhat happens
1An infected device must contact something to receive instructions
2That address was hardcoded into the botnet's code
3Investigators took control of the domain
4The devices had nowhere to check in

The infections themselves remain in place. But a device that cannot receive orders does nothing.

Cut the address, cut the connection — regardless of where the servers physically sit. Why botnets borrow other people's devices in the first place, and why routers are the preferred host, is covered in "What a botnet is."

4. What the tooling was for

The Justice Department described QScan and QTRouter as two complementary platforms, and characterized the botnet's purpose as an obfuscation network.

Obfuscation networks hide an attacker's traffic to frustrate detection. If an operation originates in one country but arrives through thousands of compromised devices in third countries, the defender's logs record only those third-party addresses.

In other words, the primary purpose of this tooling was closer to hiding than to stealing.

5. Where this sits

US-China technology confrontation ran through August in several forms. This publication covered pressure to pick sides in "The Pax Silica letters — the US tells 35 countries to choose one AI bloc," and export controls in "What AI chip export controls are."

This episode is a different layer of the same contest. It played out in network infrastructure rather than in chips or alliances, and the instrument the US reached for was neither sanctions nor tariffs but a court order.

6. What we could not confirm

  • Domain count — access to the Justice Department release was blocked; the number seized is unknown to us.
  • Device count — described only as thousands.
  • Platform roles — the technical split between QScan and QTRouter was not confirmed. The names suggest scanning and router relay; we do not assert it.
  • Exfiltration — what was taken from each agency does not appear in public materials.
  • Hospitals — reported by one outlet, not confirmed against the release.
  • Chinese response — no official statement located.

Sources

  1. US Department of Justice — Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
  2. TechCrunch — US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate
  3. CNBC — Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents
  4. CNN — US says Chinese hackers hit hospitals, NASA, Senate and more
  5. CNY Central — DOJ says China-linked hackers breached NASA, Federal Reserve and Senate networks

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • The number of domains seized was not confirmed. Direct access to the Justice Department release was blocked, so this piece relies on secondary reporting
  • The number of compromised devices was described only as thousands; no precise figure was confirmed
  • The technical division of labor between QScan and QTRouter was not confirmed against primary documents. The names suggest scanning and router relay, but this piece does not assert it
  • What data was exfiltrated from each victim agency, and in what volume, does not appear in public materials
  • The report that hospitals were among the targets comes from one outlet and was not confirmed against the Justice Department release
  • No official response from the Chinese government was located
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related