Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FBI Takes Down Chinese Hacking Platforms Targeting U.S.

FBI Takes Down Chinese Hacking Platforms Targeting U.S.

Posted on August 26, 2026 By CWS

The United States Department of Justice (DoJ) announced on Wednesday a significant disruption of two cyber platforms, QScan and QTRouter, operated by Chinese state-sponsored hackers. These platforms were designed to infiltrate critical U.S. infrastructure and sensitive networks.

Chinese State-Sponsored Cyber Activities

The hacking operations have been linked to a Chinese group known as QTFY, which was employed by Nanjing Xinjiuwei Network Technology Company. This group targeted prominent U.S. institutions, including NASA, the Federal Reserve, and multiple federal departments. Security expert Damon Rouse from Lumen Black Lotus Labs, who monitored these actions for over 18 months, noted that Nanjing Xinjiuwei collaborates with China’s Ministry of State Security and the People’s Liberation Army.

In response to these attacks, Lumen began working with the U.S. Federal Bureau of Investigation (FBI) approximately a year ago. Their research uncovered that the cybercriminals particularly targeted research institutions around the world, exploiting the collaborative nature of scientific communities.

Technical Breakdown of QScan and QTRouter

FBI Director Kash Patel highlighted that the dismantled platforms were tools for Chinese hackers to obscure the origins of their cyber intrusions. QScan was used to scan and infect IoT devices, subsequently integrating them into the QTRouter network. This network consisted of compromised devices and a mix of commercial proxy services and leased virtual private servers (VPSs).

QTRouter served as a clandestine network to mask the true origins of cyber attacks, making it appear as though they originated from locations outside China. This obfuscation was crucial for the hackers to remain undetected within targeted networks.

Impact and Future Implications

With the shutdown of the domains hard-coded into these hacking tools, their operations have been effectively halted. The distributed architecture of these tools included additional components like Fast Labyrinth and QTProxy, which provided a sophisticated relay network to disguise cyber activities.

Since its inception in 2018, QTFY has been involved in developing malicious software, trading exploits, and setting up an obfuscation botnet. Their operations targeted critical U.S. systems, facilitated by connections within China’s cyber-enabling businesses and former military personnel.

Lumen emphasized the industrial scale at which these cyber operations were conducted, indicating a shift toward more organized and anonymous cyber campaigns. The use of legitimate commercial proxy services complicates traditional cybersecurity measures, necessitating new strategies to combat such threats.

The Hacker News Tags:Botnet, China, cyber attack, cyber threats, Cybersecurity, FBI, Hacking, Infrastructure, IoT, Nanjing Xinjiuwei, QScan, QTFY, QTRouter, Security, U.S. government

Post navigation

Previous Post: Critical Bug in WordPress Plugin Risks 400,000 Sites
Next Post: Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts

Related Posts

Why Your Security Culture is Critical to Mitigating Cyber Risk Why Your Security Culture is Critical to Mitigating Cyber Risk The Hacker News
Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More The Hacker News
SafePal Data Breach Exposes 40,000 Customer Records SafePal Data Breach Exposes 40,000 Customer Records The Hacker News
OpenAI Introduces GPT-5.6-Cyber for Advanced Cybersecurity OpenAI Introduces GPT-5.6-Cyber for Advanced Cybersecurity The Hacker News
AI Chatbots Lead Users to Cryptojacking Malware Sites AI Chatbots Lead Users to Cryptojacking Malware Sites The Hacker News
Mitigating Risks of Exposed Endpoints in LLM Infrastructure Mitigating Risks of Exposed Endpoints in LLM Infrastructure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts
  • FBI Takes Down Chinese Hacking Platforms Targeting U.S.
  • Critical Bug in WordPress Plugin Risks 400,000 Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts
  • FBI Takes Down Chinese Hacking Platforms Targeting U.S.
  • Critical Bug in WordPress Plugin Risks 400,000 Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark