Close Menu
Firearms Forever
  • Home
  • Hunting
  • Guns
  • Defense
  • Videos
Trending Now

Will airmen trust AI? The Air Force’s future plans depend on it

September 20, 2026

Russia Prepares FALSE FLAG NATO Attack – Mass Casualties Expected

September 20, 2026

Bikini Atoll’s Sunken ‘Ghost Fleet’ 80 Years After Nuclear Tests

September 20, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Firearms Forever
SUBSCRIBE
  • Home
  • Hunting
  • Guns
  • Defense
  • Videos
Firearms Forever
Home»Defense»FBI disables China-linked hacking tools used against US agencies
Defense

FBI disables China-linked hacking tools used against US agencies

Tim HuntBy Tim HuntAugust 29, 20263 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

The FBI seized three internet domains Wednesday that prosecutors say Chinese government-backed hackers used to target U.S. agencies, critical infrastructure and other networks.

The Justice Department attributed the tools, known as QScan and QTRouter, to a hacking group called QTFY. Court records say the group operates through Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services to China’s main civilian intelligence agency and its military.

The group targeted networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the Energy, Justice and Health and Human Services departments, according to an FBI affidavit. Hospitals, telecommunications providers, power companies, banks and defense contractors were also targeted.

The filing does not say that every attempted attack succeeded. A 2019 attempt against NASA, for example, failed because the agency had already fixed the security flaw the hackers tried to exploit.

China’s embassy in Washington, D.C. did not immediately respond to a request for comment. Chinese officials have repeatedly denied Beijing sponsors hacking operations against the United States.

QScan was used to look for weak spots while QTRouter helped the hackers hide. QScan searched the internet for vulnerable systems and tried to break into them. QTRouter sent the hackers’ traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers. The setup was meant to make the activity appear to come from somewhere other than China.

QScan carried code for more than 200 different attacks and could work on a massive scale. On one day in 2024, it processed more than 2 million scanning or exploitation tasks, according to the affidavit.

Lumen Technologies, which tracked the same infrastructure for roughly a year, described the operator as an “infrastructure quartermaster” that provided other China-linked hackers with a ready-made service for finding targets and hiding their tracks. Lumen said networks first examined by QScan were later seen communicating through the group’s concealed network, suggesting some operations had moved from scouting targets toward attempts to break in. The system also mixed malicious traffic with that of ordinary internet users, making it harder to spot and block.

“These tools were used by PRC cyber actors to hide the origin of their attacks,” FBI Director Kash Patel said Wednesday.

Investigators said QTFY could take advantage of newly discovered security flaws quickly and at a large scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations, according to court documents.

Several months later, the hackers allegedly used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.

Investigators also tied the group’s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea and an insurance organization in Missouri.

The case highlights how Chinese intelligence and military agencies continue to heavily rely on private companies for cyber operations and services. 

Wednesday’s announcement follows years of similar FBI operations against Chinese hacking infrastructure. The bureau last year removed PlugX surveillance malware from more than 4,200 U.S. computers infected by another state-backed hacking group.

Federal authorities have also dismantled a network of compromised routers, cameras and other devices associated with Flax Typhoon and disrupted a separate network used by prominent Chinese hacking collective Volt Typhoon to hide attacks against U.S. critical infrastructure.



Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleTrump Signs Order for US Space Academy for Space Force, NASA
Next Article A Guide for First-Time Military Buyers

Related Posts

Will airmen trust AI? The Air Force’s future plans depend on it

September 20, 2026

Bikini Atoll’s Sunken ‘Ghost Fleet’ 80 Years After Nuclear Tests

September 20, 2026

8 Famous Cartoon Voice Actors Who Were Military Veterans

September 20, 2026

Marine Corps Enlistment Bonuses Offer Up to $15,000 in 2027

September 20, 2026

How the Army Used ‘Ghost Tapes’ for Psychological Warfare in Vietnam

September 19, 2026

10 Military Movies Based on Incredible True Stories

September 19, 2026
Don't Miss

Russia Prepares FALSE FLAG NATO Attack – Mass Casualties Expected

By David HooksteadSeptember 20, 2026

Watch full video on YouTube

Bikini Atoll’s Sunken ‘Ghost Fleet’ 80 Years After Nuclear Tests

September 20, 2026

Missiles TORCH The Middle East – Major Airport BOMBED

September 20, 2026

8 Famous Cartoon Voice Actors Who Were Military Veterans

September 20, 2026

Subscribe to Updates

Get the latest firearms news and updates directly to your inbox.

  • Home
  • Privacy Policy
  • Terms of use
  • Contact
© 2026 Firearms Forever. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.