US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

A major blow has been dealt to state-sponsored hackers operating out of China, as the US government announced that it has disrupted a hacking platform and botnet used by these actors. The platform, operated by a company called Nanjing Xinjiuwei Network Technology, was used to launch attacks against military and critical infrastructure systems in the United States.

At the heart of the disruption are two key services offered by the hackers: QScan, a scanning and exploitation platform that identifies vulnerable IoT devices; and QTRouter, an obfuscation network that enables threat actors to abuse compromised devices to evade detection. According to the Justice Department, US authorities identified and seized domains used by these services, rendering them inoperable.

QTFY, the state-sponsored group behind the hacking platform, has been operating since 2018 and has offered its services to the Chinese government and others. The group’s activities have been extensive, with attacks targeting sectors such as defense, local government, telecoms, and higher education. In some cases, these attempts were unsuccessful, but in others, they appear to have been successful at least to some extent.

The hackers exploited vulnerabilities in a range of products from various companies, including BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure. The FBI notes that QTFY actors are active in the exploit development community and have business relationships with entities connected to other known cyber threat groups.

The disruption of this hacking platform is a significant step forward for US cybersecurity efforts. It sends a clear message that the US government will not tolerate state-sponsored hacking activities aimed at its critical infrastructure. However, it also highlights the ongoing threat posed by these actors and the need for continued vigilance and investment in cybersecurity measures.

As a result of this disruption, individuals and organizations can take steps to protect themselves from similar attacks. Regularly updating software and systems, implementing robust security protocols, and monitoring network activity can help prevent exploitation by threat actors. Additionally, being aware of the latest vulnerabilities and exploits can inform more effective risk management strategies.

The US government’s efforts to disrupt state-sponsored hacking platforms are a crucial aspect of maintaining national cybersecurity. By targeting these groups and their infrastructure, authorities aim to reduce the threat posed by these actors and protect critical systems from further exploitation. As this story unfolds, it will be essential for security professionals and individuals alike to stay informed about emerging threats and best practices for mitigating them.


Source: SecurityWeek — 2026-08-27