Current News

/

ArcaMax

FBI investigation leads to seizure of Chinese hacking platforms

Alex Riggins, The San Diego Union-Tribune on

Published in News & Features

SAN DIEGO — An investigation led by the FBI’s San Diego field office has resulted in a takedown of online networks that were allegedly used by state-sponsored Chinese hackers to target federal agencies, large corporations and critical infrastructure across the United States and more than 130 other countries, the FBI and U.S. Department of Justice announced Wednesday.

Authorities said the U.S. targets of the hacking group known as QTFY included the military, NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services and the Senate. QTFY also allegedly targeted defense contractors, financial institutions, utility providers, public universities, hospital systems and additional government agencies at the local, state and federal levels.

The FBI said it seized three domains linked to the group that were used to conceal the cyberattacks dating back to at least 2018. In conjunction with those seizures, the FBI and the National Security Agency released a 36-page cybersecurity alert detailing some of QTFY’s alleged activities.

“These tools were used by (People’s Republic of China) cyber actors to hide the origin of their attacks,” FBI Director Kash Patel said in a statement. “Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down.”

Officials from the FBI’s San Diego field office told the Union-Tribune that the QTFY investigation was based here in part because the group “targeted and successfully exploited San Diego victims.” The officials declined to identify what San Diego entities were hit by QTFY, but said there was another key reason why the investigation began here.

“(We had) a San Diego entity come forward, share a little tidbit of information, (and then) you get very talented people like the case agents who start pulling at that thread,” FBI San Diego Supervisory Special Agent Brett Lally told the Union-Tribune. “And then it blossoms into this great understanding of what’s going on — very unique insight into what the adversary is doing. But again, it all hinged on someone coming forward and sharing a little bit of information with us.”

QTFY allegedly used two main networks to help hide its hacking activities and allegedly sold access to those networks to other hackers. One network was known as QScan and was used to scan and exploit vulnerable Internet of Things devices — essentially non-traditional devices that connect to the internet, such as smart thermostats and refrigerators.

The other tool was called QTRouter and allegedly created a botnet, or a network of infected smart devices, that the hackers could use to route their traffic through in order to obfuscate their identities and locations.

For example, if an IP address in China tried accessing a secure network of a U.S. government agency based in San Diego, that could set off alarm bells for the U.S. agency’s cybersecurity experts or law enforcement. But if the same intrusion was routed through the IP address of a hacked smart device in San Diego, it might not raise the same red flags.

“That’s a strategic decision that (QTFY) … and others are taking to create and maintain access to infected devices in America, to use them against us, to use them in hacking attacks against the United States,” Lally said.

Once QTFY allegedly used its QScan and QTRouter tools to infect smart devices and create the botnet, it used more sophisticated hacking techniques to actually invade the networks of the government agencies and other entities it was targeting.

 

“The advanced hacking they would do against the government agency would be a little different than they would do on somebody’s (smart) device,” an FBI San Diego case agent told the Union-Tribune. The FBI asked that the agent’s identity be protected due to the sensitive nature of his work.

The case agent said one particular intrusion in September 2024, also detailed in the FBI and NSA’s joint cybersecurity advisory, made use of what’s known as a zero-day attack.

“What a zero-day attack means is they’ve found an exploit that nobody knows about, and that there’s no way to stop it because nobody knows about it,” the case agent said. “They successfully compromised … devices at three large Department of Energy laboratories, the National Institutes of Health and a large U.S. security device company.”

The case agent said the group also exploited artificial intelligence research and technology in its advanced hacking. “They’re experts at finding vulnerabilities, including … zero-day exploits, and leveraging them against high-value targets,” the case agent said.

Federal authorities alleged that QTFY is part of a larger Chinese firm, the Nanjing Xinjiuwei Network Technology Company, that supports government-backed hacking units. Authorities alleged that some of the hackers employed by QTFY previously served in China’s People’s Liberation Army.

Mark Remily, special agent in charge of the FBI’s San Diego field office, told the Union-Tribune that QTFY sold network access and stolen data to customers that include China’s Ministry of State Security and the People’s Liberation Army.

In an affidavit supporting the seizures of the internet domains, an FBI agent wrote that payments from China’s Ministry of State Security to Nanjing Xinjiuwei “indicate that the company conducts malicious cyber activities on behalf of the PRC Government.”

Authorities said the three domains seized Wednesday were hard-coded into both the QScan and QTRouter malware, meaning the seizure would make those networks inoperable.

Officials said the U.S. Attorney’s Office in San Diego was also involved in the QTFY investigation, though it was unclear if the case would result in criminal charges against individuals allegedly associated with QTFY.

_____


©2026 The San Diego Union-Tribune. Visit sandiegouniontribune.com. Distributed by Tribune Content Agency, LLC.

 

Comments

blog comments powered by Disqus