Thursday, August 27, 2026|20°C Partly Cloudy
Next edition scheduled
Your Personal Daily Intelligence
Today's edition

TECHNOLOGY

FBI Seizes Hacking Platforms Used in Cyberattacks on U.S. Government Networks

FBI on Wednesday said it disrupted a botnet and seized two platforms that a Chinese government‑backed group used to compromise NASA, the U.S.

By theregister · 3h ago · Source: theregister

Full article

FBI on Wednesday said it disrupted a botnet and seized two platforms that a Chinese government‑backed group used to compromise NASA, the U.S. Senate, the Department of Energy and other critical networks. The seizure rendered the services inoperable.

The platforms, named QScan and QTRouter, were operated by the group QTFY, which the FBI says is linked to a private company, Nanjing Xinjiuwei, and receives payments from China’s Ministry of State Security, according to court documents. QTFY members include former People’s Liberation Army personnel who use military connections to secure contracts for offensive cyber operations.

QScan automatically scans the internet, infects thousands of IoT devices and adds them to the QTRouter network, which includes compromised IoT devices, commercial proxy services and leased virtual private servers. The combined infrastructure functions as an obfuscation layer that hides the origin of intrusion activity. On Monday, a U.S. federal court issued seizure warrants for the domains qtproxy.xyz, qt-proxy.org and qt-team.com, which were hard‑coded into both malware families. The court‑authorized takedowns disabled the hacking services, the Justice Department said.

The malware and services have been in use since at least 2018. They were employed in a 2019 attempt to exploit the CVE‑2019‑11510 vulnerability in Ivanti Pulse Secure VPN against NASA, a flaw that was patched in April 2019. China also used the zero‑day to breach defense contractors, government agencies and financial institutions. In 2020 the group leveraged the same vulnerability to attack a medical center in Ohio, and in subsequent years targeted financial firms in Michigan and South Korea, a Missouri insurance agency via a Citrix VPN flaw, three Department of Energy national laboratories, the National Institutes of Health and a U.S. security device manufacturer, according to court filings.

The latest seizure follows a series of court‑ordered actions against Chinese cyber‑operatives. In 2025 the FBI removed PlugX malware from more than 4,000 U.S. computers infected by the Mustang Panda group. In 2024 Chinese authorities dismantled a botnet tied to the Flax Typhoon operation. In late 2023 the FBI disrupted a Volt Typhoon‑linked botnet used against critical infrastructure, and a 2024 report noted a resurgence of that botnet affecting roughly 1,500 compromised routers and IoT devices, according to Lumen’s Black Lotus Labs.

The FBI did not respond to inquiries about the total number of devices compromised or whether the actors have ties to China’s “Typhoon” hacking groups.

Source transparency

Publisher
theregister
Reliability
high
Published
8/27/2026, 10:00:21 AM
Retrieved
8/27/2026, 10:00:21 AM
Relevance
80%
Confidence
85%
Read original at theregister

Botwin's Morning Wire publishes the full source article for reading convenience. Please visit the publisher for the original presentation and any updates.