XOOMAR
Monochrome image of a masked hacker on a video call, showcasing cyber security themes.
CybersecurityAugust 29, 2026· 7 min read· By XOOMAR Insights Team

Chinese Hackers Infiltrated NASA and Senate for Eight Years

Share
Updated on August 29, 2026

The U.S. Department of Justice has publicly exposed a massive, persistent Chinese cyber espionage campaign targeting the nation’s most sensitive nerve centers, including the U.S. Senate, NASA, and the Federal Reserve, according to Time. An FBI affidavit unsealed Wednesday details a seven-year operation, active since 2018, that went beyond government networks to systematically target hospitals, power companies, and defense contractors. This isn’t a single data breach. It’s a strategic intelligence blueprint for mapping and exploiting America’s foundational systems.

XOOMAR Intelligence

Analyst Take

70/ 100
High
4 sources analyzedMedium confidenceTrend10Freshness99Source Trust88Factual Grounding78Signal Cluster20

Mapping an Eight-Year Campaign Across Critical Sectors

The scope outlined in court documents is breathtakingly broad, moving from symbolic government pillars to the utilities of daily life.

Government & Science: The operation targeted networks belonging to NASA, the Department of Energy, the Justice Department, the Federal Reserve, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The affidavit notes these were not always successful intrusions. For instance, hackers failed to exploit a VPN vulnerability at NASA in August 2019 and were blocked from the Senate in a March 2026 scan.

Critical Infrastructure & Industry: The campaign’s real breadth is in its private-sector focus. The affidavit explicitly accuses the group, called QTFY, of targeting networks “operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.” A joint FBI, NSA, and Cyber Command advisory confirms successful intrusions at three unnamed Department of Energy National Laboratories, the NIH, and an HHS agency in September 2024.

XOOMAR Interpretation: The target list is a direct read of U.S. strategic vulnerabilities: energy grids for potential disruption, health agencies for research and pandemic-era intelligence, financial institutions for economic insight, and defense contractors for technological secrets. This campaign was a systematic effort to collect intelligence across every domain that matters in a potential geopolitical crisis.


The Quartermaster's Toolkit: How Hackers Hid for Nearly a Decade

The longevity of the operation, from 2018 through 2026, points to sophisticated tradecraft designed to evade detection. The FBI says the core of the scheme was two interconnected platforms operated by QTFY.

QScan was a tool for automatically scanning and compromising thousands of Internet of Things (IoT) devices worldwide. QTRouter then assembled these hacked devices, plus commercial proxies and leased servers, into a massive obfuscation network. This allowed QTFY and its paying customers to route their attack traffic, making it appear to originate from a local, compromised device near the target rather than from China.

The infrastructure was allegedly run through a private company, Nanjing Xinjiuwei Network Technology Company, whose employees include former members of China’s People’s Liberation Army. The FBI affidavit states these actors “use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations.” Payments from China’s Ministry of State Security to the company indicate it “conducts malicious cyber activities on behalf of the PRC Government.”

This setup created a resilient, deniable ecosystem. As we reported in FBI Seizes Beijing's Private Quartermaster in Cyber Espionage Strike, such proxy services act as force multipliers for state-backed hackers, blending their traffic into the noise of the everyday internet.

A Calculated Disruption, Not a Deterrence

The U.S. response was a focused infrastructure takedown, not a diplomatic broadside. At the core was a legal and technical maneuver: the FBI, with a court order, seized three internet domains (qtproxy.xyz, qt-proxy.org, and qt-team.com) that were hardcoded into the QScan and QTRouter malware. By taking control of these central command points, the Justice Department rendered both hacking platforms inoperable.

“This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop,” Attorney General Todd Blanche told Fox News.

The action mirrors previous botnet disruptions but is notable for its detailed, public attribution tying the activity directly to a Chinese company and, by extension, state security services. The U.S. simultaneously released a joint cybersecurity advisory with technical indicators to help network defenders identify and eject the hackers from compromised systems.

However, the DOJ announcement did not specify any criminal charges or arrests. The spokesperson for the Chinese Embassy in Washington pushed back, calling China a “firm defender” of cybersecurity and urging the U.S. to stop “using such issues to ‘smear or discredit’ the country.” This public naming-and-shaming occurs just a month before Chinese leader Xi Jinping is expected to visit the U.S., framing cybersecurity as a persistent, unresolved tension.

XOOMAR Analysis: This takedown is a tactical win that disrupts a specific toolset, but it does not address the underlying operational model. The affidavit shows that when one vulnerability is patched (like the Ivanti VPN flaw exploited in 2019), the group simply pivots to another (like a zero-day against Ivanti Cloud Services Appliance in 2024). The resources and mandate appear persistent.


What the QTFY Campaign Reveals About Modern Digital Defense

The QTFY affidavit is a case study in why traditional perimeter-based security is obsolete against a determined nation-state.

The Perimeter is Everywhere: The hackers didn’t just attack government firewalls. They compromised thousands of poorly secured consumer IoT devices globally to build their attack network. This means a vulnerable smart thermostat in a home router halfway around the world became a potential launchpad for an attack on a U.S. hospital. Defense must now account for the security of the entire digital ecosystem, not just one's own servers.

Living in the Enterprise: The group’s ability to maintain access inside victim networks for years suggests they expertly used “living off the land” techniques, leveraging legitimate administration tools already present in the systems to avoid triggering malware alerts. This necessitates a zero-trust internal architecture, where continuous verification is required even for traffic already inside the network.

The Human-Intel Link: The operation’ alleged structure, using a private company staffed by former military personnel, highlights the blurry line between state and commercial hacking. It creates plausible deniability for Beijing while providing a career path and contractor payments for skilled operators. For defenders, it means threat intelligence must track corporate structures and hiring patterns as closely as malware signatures.

As incidents like the Ransomware Gang Hacks ATF Investigation Database show, even well-resourced agencies are vulnerable. The QTFY campaign underscores that the most critical networks are under a constant, patient, and well-funded siege.

Watch the Infrastructure, Not Just the Exploit

The key takeaway from this eight-year campaign is a shift in what to monitor. The exploit of the week matters less than the infrastructure that enables years of exploitation.

Watch for the Rebuild: The seizure of the QTRouter domains is a significant blow, but as seen with the Volt Typhoon group, which saw a “significant resurgence” of its botnet after a 2023 disruption, these groups often regroup. Cybersecurity firms and agencies will be watching for the redeployment of similar proxy services under new domain names and code.

Watch the Corporate Veil: The use of Nanjing Xinjiuwei as an operational arm is a model other state actors may emulate or that China may replicate elsewhere. Increased scrutiny of the contracts and client lists of niche cybersecurity firms in adversarial nations will become a crucial intelligence function.

Watch the Escalation Ladder: The U.S. has chosen a path of public exposure and infrastructure takedown short of kinetic retaliation. The question is whether this repeated cycle of catch-and-release attribution is viewed as an acceptable cost of doing business for adversaries. The targeting of critical infrastructure like power and water, even if for intelligence gathering, flirts with red lines. The next phase may involve more aggressive defensive actions taken inside compromised networks to not just eject hackers, but to disable their capability to return.

Impact Analysis

  • This campaign reveals systematic mapping of America's most critical systems—from government institutions to power grids—creating strategic vulnerabilities that could be exploited during geopolitical tensions.
  • Successful intrusions at national laboratories and health agencies mean sensitive research, economic data, and public health intelligence may have been compromised for years.
  • The seven-year operation demonstrates the persistent threat to national security and daily civilian life, highlighting the need for enhanced cybersecurity across both public and private sectors.

Targeted Sectors in Chinese Cyber Espionage Campaign

SectorPrimary TargetsNotable Outcomes
Government & ScienceNASA, U.S. Senate, Federal Reserve, Department of Energy, Justice Department, NIH, HHSSome intrusions blocked (e.g., NASA VPN in Aug 2019, Senate in Mar 2026)
Critical InfrastructureHospitals, power companies, telecommunications providersSuccessful intrusions reported at three Department of Energy National Labs (Sep 2024)
Industry & DefenseFinancial institutions, defense contractorsPart of systematic intelligence gathering operation since 2018
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Laptop screen showing 'Proxy provider' in a tech office setting, focus on cybersecurity.Cybersecurity

FBI Seizes Beijing's Private Quartermaster in Cyber Espionage Strike

The FBI seized the core infrastructure of a Chinese company that acted as the quartermaster for state-sponsored hackers, disrupting a vast, centralized system u

Aug 26, 20267 min
Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.Cybersecurity

Chinese Telcos Still Run U.S. Network Backdoors, Report Warns

A U.S. House committee report finds China's state-owned telecom giants maintain deep, persistent access points within American networks despite being officially

Aug 6, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

DOJ Seizes Chinese Hackers After 300 Financial Hits

The U.S. Department of Justice seized infrastructure used in a widespread Chinese state hacking campaign that compromised over 300 organizations, including fina

Aug 28, 20266 min
Wooden letter blocks spelling 'CYBER SECURITY' on a wooden grid background for data protection themes.Cybersecurity

100 Cities Lose Control of Water Supply in Cyber Siege

Over 100 U.S. water systems were directly targeted and breached in a single month, as hackers sabotaged industrial hardware controlling the water supply, forcin

Aug 27, 20266 min
Cyber security concept shown on grunge-style background highlights the importance of digital protection.Cybersecurity

Iran Cyberattack Shuts UK Power Plant Amid US Sanctions

US sanctions target six Iranian hackers following a destructive cyberattack that forced a UK power plant offline for four days, signaling a sharp escalation aga

Aug 25, 20264 min
Close-up of smartphone on wooden surface displaying a bank alert message.Fintech

Fed Chair Warsh Dodges Crisis With Vague Jackson Hole Talk

New Fed Chair Warsh delivered a deliberately vague Jackson Hole speech, offering high-level philosophy instead of concrete guidance on inflation and bond market

Aug 28, 20265 min
Hands holding a smartphone displaying a world map on a white background.Global Trends

China Warns of Himalayan Dam Collapse Within Days

A 2.5 million cubic meter barrier lake formed by a landslide near the Nepal-Tibet border is at high risk of bursting, threatening a second catastrophic flood an

Aug 28, 20265 min
Female engineer using laptop to analyze vehicle data inside a car for testing purposes.SaaS & Tools

Ex-Engineer Maps a $60,000 Mistake Beneath America

A former PG&E engineer's startup raised a $26 million Series A to build a unified map of underground utilities, after a single unknown pipe cost him $60,000.

Aug 29, 20267 min
From above of sunlit aged paper world map with continents countries and oceansGlobal Trends

CIA Chief Warns Russia Against NATO Attack in Moscow

The CIA director made a secret trip to Moscow to personally warn Russia against any attack on NATO members, a private confrontation the Kremlin publicly dismiss

Aug 29, 20266 min
A music producer in a home studio using advanced technology to create music.Technology

Musicians Hunt AI Grifters as Suno Floods EDM

Musicians are using forensic audio analysis to expose AI-generated fakes, as platforms like Suno threaten careers and warp entire creative scenes.

Aug 29, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.