US Seizes Chinese Hacking Platforms, Links Them to State Security and Military
The US Department of Justice announced on August 26 that it had seized the domain names of two hacking platforms, QScan and QTRouter, which were allegedly operated by a company in Nanjing, China, and used by a Chinese state-sponsored hacking group known as QTFY. The victims of the hacking included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the National Institutes of Health, and the US Senate.
According to court documents released by the US Department of Justice, the FBI and the Department of Justice seized the domain names used by QScan and QTRouter. The US claimed that the two platforms were created and operated by Nanjing Xingjiuwei Network Technology Co., Ltd., a company based in China, and were used by QTFY, a Chinese state-sponsored hacking group. The US government stated that the seizure of the domain names, which were hardcoded into malware and used for communication and authentication, had rendered the two platforms inoperable.

The list of victims suggests that this was not an ordinary case of commercial cybercrime. The Department of Justice listed targets including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The fact that aerospace, finance, energy, justice, biomedicine, and legislative institutions were all targeted simultaneously gives the case a clear national security attribute.
More importantly, the US government described the chain of responsibility. The Department of Justice stated that QTFY personnel were employed by Nanjing Xingjiuwei, and that the activities were connected to the Chinese state-sponsored system. The US National Security Agency and the FBI released a technical security advisory on the same day, publishing technical indicators of the malicious cyber activity and tracing the activity back to at least 2018.
This brings the long-standing issue of attributing cyberattacks to a new stage. Diplomatic statements can be mutually denied, but court seizures require investigators to submit materials to judges; technical attribution can be debated, but domain names, servers, malware, employees, customers, and financial transactions can form a chain of evidence.
原始来源 · justice.govJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical InfrastructureThe Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.justice.gov ↗The US Department of Justice also placed this action in a continuous record of law enforcement against Chinese state-sponsored cyber activities: disrupting the Volt Typhoon botnet in 2023, striking the Flax Typhoon infrastructure in 2024, and removing PlugX surveillance malware related to Mustang Panda from over 4,000 US computers in 2025.
The question that Beijing needs to answer is no longer just a statement that "China is also a victim of cyberattacks." The real question is: what kind of business, task, and personnel relationship exists between Chinese national security agencies and military, and domestic network security companies? Are national projects implemented through commercial companies? Are attack infrastructures provided by so-called private enterprises? Why can't government contracts, funding sources, and customer lists of these companies be subject to independent review?
Xi Jinping has repeatedly emphasized technological self-reliance, cyber power, and overall national security, while the US judicial system is leaving a record from another direction: a number of Chinese commercial technology companies have been accused of being an intermediate layer between national cyber activities and government agencies.
If this "state agency
- contracting company
- hacking platform
- overseas target" chain is eventually confirmed by more judicial evidence, the Chinese Communist Party will face not only a cyberattack accusation but also a more serious international credibility issue: whether Beijing is using seemingly civilian commercial companies to provide a deniable cover for national intelligence and military cyber activities.

文章讨论
已验证会员可围绕报道公开交流,并自行管理自己的内容。
正在检查会员登录状态…