FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

The US Department of Justice and FBI have dismantled a Chinese state-sponsored hacking operation that utilized proxy tools to infiltrate major US government agencies and infrastructure. The operation, linked to a Nanjing-based contractor, targeted entities including NASA, the US Senate, and various critical infrastructure providers.
Why it matters
This highlights the growing threat of state-sponsored cyber espionage and the increasing reliance of governments on private contractors to facilitate large-scale infrastructure attacks.
On Wednesday, the Department of Justice announced the takedown of two tools, known as QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY, which is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company. According to prosecutors and an FBI affidavit used to seize domains that those tools relied on, the company gave its customers access to botnets of hacked internet-of-things (IoT) devices and co-opted commercial proxy services. The company's customers—allegedly including the Ministry of State Security and the People's Liberation Army—then used those proxy services as relay points to carry out hacking campaigns stretching back as early as 2018, according to the US government.
The report relies on official government statements and threat intelligence findings, maintaining a factual tone regarding national security events.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in