• 3 min read
Chinese hackers used an IoT botnet to breach NASA and more
A Justice Department disclosure says Chinese state-backed hackers breached NASA, the Federal Reserve, the Senate and other US agencies through an IoT proxy botnet.

Image: TechRadar
Chinese state-sponsored hackers breached computers belonging to NASA, the Federal Reserve, the US Senate and multiple other federal agencies, using compromised internet-connected devices to hide the origins of their attacks.
The victims listed in a Justice Department and FBI disclosure on the disruption of the hacking infrastructure include the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate. The disclosure describes those organizations as victims of “computer intrusion.”
The operation centered on a paid hacking platform built around two services, QScan and QTRouter. QScan and QTRouter were designed to identify and infect internet-connected devices, then use those devices as nodes in a proxy network. Traffic routed through the compromised systems made it harder for investigators and target networks to identify the attackers' real infrastructure.
That architecture puts poorly secured IoT equipment between the attacker and the target. The devices obscure the network origin and complicate attribution. The disclosure says the platforms were used to infiltrate US critical infrastructure, but it does not provide the number of affected devices, identify the specific systems accessed inside each agency or describe how long the intrusions lasted.

Recommended reading
PaperCut warns of active zero-day attacks on print servers
Sophia Reynolds • • 4 min read
QTFY and the seized infrastructure
Court documents unsealed by the Southern District of California identify the disrupted hacking group as QTFY. The group was apparently hired by Nanjing Xinjiuwei Network Technology Company to create and operate QScan and QTRouter. Chinese hackers then used the services to conduct intrusions while masking their traffic through the IoT proxy network.
The Justice Department and FBI seized adversary infrastructure and shut down the two platforms. That action targets the control and access layer used to conduct the attacks, but the disclosure does not say that every compromised IoT device was cleaned or that all persistence inside victim networks was removed.
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking — and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”
The QTFY operation is one of several US technical actions aimed at limiting Chinese access to government networks and critical infrastructure. Earlier operations cited in the disclosure included removing PlugX malware from thousands of US computers and disrupting Chinese botnets that leveraged millions of unsecured IoT devices.
The immediate result is a takedown of named domains and infrastructure, not a demonstrated end to the underlying access model. QScan and QTRouter depended on exposed connected devices, so similar proxy infrastructure could be rebuilt with a different control layer unless those devices are secured or removed from the network. The government has not disclosed the agencies' individual remediation status or whether the reported intrusions caused data theft or operational disruption.
Frequently asked questions
Which US agencies were breached?+
The disclosure names NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate.
How did the Chinese hackers hide their traffic?+
QScan and QTRouter identified and infected internet-connected devices, using them as proxy nodes to obscure the origin of traffic aimed at US networks.
What happened to QScan and QTRouter?+
The FBI and Justice Department seized the adversary infrastructure associated with the platforms and shut them down.
How many devices were compromised?+
The disclosure does not state how many IoT devices were infected or how many systems inside each listed agency were accessed.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.


