The U.S. Department of Justice has publicly exposed a massive, persistent Chinese cyber espionage campaign targeting the nation’s most sensitive nerve centers, including the U.S. Senate, NASA, and the Federal Reserve, according to Time. An FBI affidavit unsealed Wednesday details a seven-year operation, active since 2018, that went beyond government networks to systematically target hospitals, power companies, and defense contractors. This isn’t a single data breach. It’s a strategic intelligence blueprint for mapping and exploiting America’s foundational systems.
XOOMAR Intelligence
Analyst Take
Mapping an Eight-Year Campaign Across Critical Sectors
The scope outlined in court documents is breathtakingly broad, moving from symbolic government pillars to the utilities of daily life.
Government & Science: The operation targeted networks belonging to NASA, the Department of Energy, the Justice Department, the Federal Reserve, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The affidavit notes these were not always successful intrusions. For instance, hackers failed to exploit a VPN vulnerability at NASA in August 2019 and were blocked from the Senate in a March 2026 scan.
Critical Infrastructure & Industry: The campaign’s real breadth is in its private-sector focus. The affidavit explicitly accuses the group, called QTFY, of targeting networks “operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.” A joint FBI, NSA, and Cyber Command advisory confirms successful intrusions at three unnamed Department of Energy National Laboratories, the NIH, and an HHS agency in September 2024.
XOOMAR Interpretation: The target list is a direct read of U.S. strategic vulnerabilities: energy grids for potential disruption, health agencies for research and pandemic-era intelligence, financial institutions for economic insight, and defense contractors for technological secrets. This campaign was a systematic effort to collect intelligence across every domain that matters in a potential geopolitical crisis.
The Quartermaster's Toolkit: How Hackers Hid for Nearly a Decade
The longevity of the operation, from 2018 through 2026, points to sophisticated tradecraft designed to evade detection. The FBI says the core of the scheme was two interconnected platforms operated by QTFY.
QScan was a tool for automatically scanning and compromising thousands of Internet of Things (IoT) devices worldwide. QTRouter then assembled these hacked devices, plus commercial proxies and leased servers, into a massive obfuscation network. This allowed QTFY and its paying customers to route their attack traffic, making it appear to originate from a local, compromised device near the target rather than from China.
The infrastructure was allegedly run through a private company, Nanjing Xinjiuwei Network Technology Company, whose employees include former members of China’s People’s Liberation Army. The FBI affidavit states these actors “use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations.” Payments from China’s Ministry of State Security to the company indicate it “conducts malicious cyber activities on behalf of the PRC Government.”
This setup created a resilient, deniable ecosystem. As we reported in FBI Seizes Beijing's Private Quartermaster in Cyber Espionage Strike, such proxy services act as force multipliers for state-backed hackers, blending their traffic into the noise of the everyday internet.
A Calculated Disruption, Not a Deterrence
The U.S. response was a focused infrastructure takedown, not a diplomatic broadside. At the core was a legal and technical maneuver: the FBI, with a court order, seized three internet domains (qtproxy.xyz, qt-proxy.org, and qt-team.com) that were hardcoded into the QScan and QTRouter malware. By taking control of these central command points, the Justice Department rendered both hacking platforms inoperable.
“This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop,” Attorney General Todd Blanche told Fox News.
The action mirrors previous botnet disruptions but is notable for its detailed, public attribution tying the activity directly to a Chinese company and, by extension, state security services. The U.S. simultaneously released a joint cybersecurity advisory with technical indicators to help network defenders identify and eject the hackers from compromised systems.
However, the DOJ announcement did not specify any criminal charges or arrests. The spokesperson for the Chinese Embassy in Washington pushed back, calling China a “firm defender” of cybersecurity and urging the U.S. to stop “using such issues to ‘smear or discredit’ the country.” This public naming-and-shaming occurs just a month before Chinese leader Xi Jinping is expected to visit the U.S., framing cybersecurity as a persistent, unresolved tension.
XOOMAR Analysis: This takedown is a tactical win that disrupts a specific toolset, but it does not address the underlying operational model. The affidavit shows that when one vulnerability is patched (like the Ivanti VPN flaw exploited in 2019), the group simply pivots to another (like a zero-day against Ivanti Cloud Services Appliance in 2024). The resources and mandate appear persistent.
What the QTFY Campaign Reveals About Modern Digital Defense
The QTFY affidavit is a case study in why traditional perimeter-based security is obsolete against a determined nation-state.
The Perimeter is Everywhere: The hackers didn’t just attack government firewalls. They compromised thousands of poorly secured consumer IoT devices globally to build their attack network. This means a vulnerable smart thermostat in a home router halfway around the world became a potential launchpad for an attack on a U.S. hospital. Defense must now account for the security of the entire digital ecosystem, not just one's own servers.
Living in the Enterprise: The group’s ability to maintain access inside victim networks for years suggests they expertly used “living off the land” techniques, leveraging legitimate administration tools already present in the systems to avoid triggering malware alerts. This necessitates a zero-trust internal architecture, where continuous verification is required even for traffic already inside the network.
The Human-Intel Link: The operation’ alleged structure, using a private company staffed by former military personnel, highlights the blurry line between state and commercial hacking. It creates plausible deniability for Beijing while providing a career path and contractor payments for skilled operators. For defenders, it means threat intelligence must track corporate structures and hiring patterns as closely as malware signatures.
As incidents like the Ransomware Gang Hacks ATF Investigation Database show, even well-resourced agencies are vulnerable. The QTFY campaign underscores that the most critical networks are under a constant, patient, and well-funded siege.
Watch the Infrastructure, Not Just the Exploit
The key takeaway from this eight-year campaign is a shift in what to monitor. The exploit of the week matters less than the infrastructure that enables years of exploitation.
Watch for the Rebuild: The seizure of the QTRouter domains is a significant blow, but as seen with the Volt Typhoon group, which saw a “significant resurgence” of its botnet after a 2023 disruption, these groups often regroup. Cybersecurity firms and agencies will be watching for the redeployment of similar proxy services under new domain names and code.
Watch the Corporate Veil: The use of Nanjing Xinjiuwei as an operational arm is a model other state actors may emulate or that China may replicate elsewhere. Increased scrutiny of the contracts and client lists of niche cybersecurity firms in adversarial nations will become a crucial intelligence function.
Watch the Escalation Ladder: The U.S. has chosen a path of public exposure and infrastructure takedown short of kinetic retaliation. The question is whether this repeated cycle of catch-and-release attribution is viewed as an acceptable cost of doing business for adversaries. The targeting of critical infrastructure like power and water, even if for intelligence gathering, flirts with red lines. The next phase may involve more aggressive defensive actions taken inside compromised networks to not just eject hackers, but to disable their capability to return.
Impact Analysis
- This campaign reveals systematic mapping of America's most critical systems—from government institutions to power grids—creating strategic vulnerabilities that could be exploited during geopolitical tensions.
- Successful intrusions at national laboratories and health agencies mean sensitive research, economic data, and public health intelligence may have been compromised for years.
- The seven-year operation demonstrates the persistent threat to national security and daily civilian life, highlighting the need for enhanced cybersecurity across both public and private sectors.
Targeted Sectors in Chinese Cyber Espionage Campaign
| Sector | Primary Targets | Notable Outcomes |
|---|---|---|
| Government & Science | NASA, U.S. Senate, Federal Reserve, Department of Energy, Justice Department, NIH, HHS | Some intrusions blocked (e.g., NASA VPN in Aug 2019, Senate in Mar 2026) |
| Critical Infrastructure | Hospitals, power companies, telecommunications providers | Successful intrusions reported at three Department of Energy National Labs (Sep 2024) |
| Industry & Defense | Financial institutions, defense contractors | Part of systematic intelligence gathering operation since 2018 |
Primary Sources & Disclosures
- [1]Time
- [2]US says Chinese hackers hit hospitals, NASA, Senate and more | CNN Politics
- [3]FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
- [4]China-Linked Hackers Targeted NASA, Federal Reserve and US Senate; FBI Seizes Hacking Platforms - The Researchers
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.










