FBI Dismantles China-Linked Hacking Network That Targeted NASA, the Senate and the Federal Reserve | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


WASHINGTON, DC – SEPTEMBER 16: Deputy Attorney General Jeffery Rosen listens as FBI Deputy Director David Bowdich speaks to the media about charges and arrests related to a computer intrusion campaign tied to the Chinese government by a group called APT 41 at the Department of Justice on September 16, 2020 in Washington, DC. The Justice Department unsealed charges on Wednesday against five Chinese citizens accused of hacking more than 100 companies in the U.S. who are allegedly members of a larger operation known as APT-41.
Photo by Tasos Katopodis-Pool/Getty Images

A years-long cyber-espionage campaign that U.S. investigators tie to the Chinese government lost its digital backbone this week, after federal prosecutors and FBI agents carried out court-authorized seizures of the domains keeping two connected hacking tools alive. The takedown lands close to home in Houston, where NASA’s Johnson Space Center anchors an aerospace economy built in part on Hispanic engineering, contracting and mission-support talent.

Two Tools, One Coordinated Operation

A newly unsealed California federal court filing lays out how a scanning platform called QScan paired with an obfuscation network called QTRouter, both built and run by a group prosecutors call QTFY. Investigators trace QTFY to a Nanjing-based firm, Nanjing Xinjiuwei Network Technology Company, which allegedly rented its intrusion capabilities to paying clients that included China’s Ministry of State Security and the People’s Liberation Army. QScan combed the internet for unsecured routers, cameras and other connected gadgets and infected them automatically. QTRouter then wove those hijacked machines together with leased servers and commercial proxy services, so an intrusion that started in China could pass for ordinary traffic from a device sitting near its target. Because the malware needed the same three domains to communicate and verify itself, seizing them left both platforms unable to function. FBI Director Kash Patel put it bluntly, saying the platforms had been “used by PRC cyber actors to hide the origin of their attacks.”

A Target List That Spans the Federal Government

Prosecutors name seven federal victims in all: NASA, the U.S. Senate, the Federal Reserve, the Energy Department, HHS, NIH and the Justice Department itself. Court filings reviewed by Fox News describe damage far wider than that roster: more than 300 organizations, among them banks, universities and defense contractors, reportedly had data taken, and separate intrusions hit three Energy Department national laboratories. On its heaviest recorded day in 2024, QScan ran upward of two million scans and break-in attempts using a toolkit of roughly 200 ready-made exploits. Not every attempt succeeded; an August 2019 push into a NASA network reportedly failed because the agency had already closed the flaw the hackers were trying to use. A joint advisory from the FBI, NSA and Cyber National Mission Force adds that hospitals, telecom carriers, power utilities and a U.S. election system were scanned as well, though several of those specific attempts reportedly came up short.

Why Houston Has a Stake in This

NASA’s presence on the target list carries particular weight in Houston, longtime home to Johnson Space Center, the agency’s hub for astronaut training and mission control since the 1960s. The center supports an active Hispanic Employee Resource Group, whose members have organized programming ranging from a mariachi ensemble to Hispanic Heritage Month events for local students.

Johnson Space Center alone employs upward of 10,000 people, part of a broader footprint that includes roughly $64 million a year in NASA contracts flowing to Hispanic-owned businesses out of the agency’s $2.5-billion-plus yearly spending statewide. A breach aimed at NASA’s systems, even one investigators say failed, shows how a hacking campaign run out of China can still touch the paychecks and job security of Latino families in Houston, Doral and other metro areas connected to the federal agencies named in the filing.

Wednesday’s seizure extends a pattern rather than standing alone. The FBI dismantled a Volt Typhoon botnet in 2023, took apart a Flax Typhoon device network in 2024, and stripped PlugX spyware off upward of 4,000 machines nationwide tied to the group Mustang Panda in 2025. Aaron Shraberg, who leads a threat-intelligence team at the cybersecurity firm Flashpoint, told Fox News the QTFY case shows how commercialized China’s hacking industry has become, with capabilities once built through custom tradecraft now able to be “developed, reused and deployed at scale” by contractors serving state clients.

Beijing Pushes Back, and What Comes Next

Attorney General Todd Blanche framed the seizures as a warning that hackers targeting American infrastructure will face consequences, describing the case as one piece of a broader national-security push rather than a closed matter. Beijing pushed back hard. Its embassy in Washington issued a statement insisting the country “opposes and combats all forms of cyberattacks in accordance with the law,” and accused U.S. officials of leaning on cybersecurity claims to unfairly target Chinese interests. Alongside the seizure, the FBI, NSA and Cyber National Mission Force published technical indicators tied to QTFY activity stretching back to 2018, giving network administrators a way to check whether their own systems were ever touched.

© {{Year}} Latin Times. All rights reserved. Do not reproduce without permission.



Click Here For The Original Source.

——————————————————–

..........

.

.