• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / DOJ seizes domains linked to Chinese state-sponsored hackers

DOJ seizes domains linked to Chinese state-sponsored hackers

byLotfi Ben Taleb
August 26, 2026
in Security
Reading Time: 3 mins read
Close-up of a network switch with red, yellow, and green ethernet cables plugged into ports
Share on Facebook
Share on Twitter

The US Department of Justice and FBI seized three domains on Wednesday that they say Chinese state-sponsored hackers used to run a botnet behind intrusions at several federal agencies, including:

  • NASA
  • The US Senate
  • The Federal Reserve
  • The Department of Energy
  • The Department of Justice
  • The Department of Health and Human Services
  • The National Institutes of Health

According to the Justice Department’s announcement, the intrusions were carried out by a group it identifies as QTFY, using two purpose-built malware tools called QScan and QTRouter. The department says the People’s Republic of China’s Ministry of State Security was one of QTFY’s paying customers, and that the group operates through a company it names as the Nanjing Xinjiuwei Network Technology Company.

The three seized domains, qtproxy.xyz, qt-proxy.org and qt-team.com, now display a federal seizure notice. The unsealed affidavit traces the operation back to 2018 and describes QScan as software that scans for and automatically infects thousands of internet-of-things devices worldwide, folding each one into the QTRouter network.

How Chinese state-sponsored hackers ran the QTRouter botnet

Once a device is compromised, QTRouter turns it into what the Justice Department calls an obfuscation layer, a hop that routes attack traffic through someone’s infected home router or smart device rather than through infrastructure that traces back to the operator. That is a standard technique in state-linked intrusion sets, and it is why this action targets domains and command infrastructure rather than the individual devices doing the routing, since the FBI cannot practically clean every infected router.

Tom’s Hardware reports that the FBI’s investigation dates back to 2019, when agents examined a NASA intrusion tied to CVE-2019-11510, a Pulse Secure VPN vulnerability patched years ago. They traced the activity to two Gmail accounts and a phone number carrying China’s +86 country code, and found the group had rented infrastructure from commercial hosts, which prompted a string of abuse complaints to those Gmail addresses from hosting provider Hostwinds. The three seized domains were registered between 2022 and 2024.

Eight years between first breach and seizure

By teqpost’s arithmetic, eight years separate the first documented compromise attributed to Chinese state-sponsored hackers in 2018 from Wednesday’s seizure. That gap says as much about the mechanics of a case like this as it does about the group: the affidavit shows years spent tying anonymous Gmail accounts and rented servers to a single operation before there is enough evidence to seize even three domains. It also underlines a structural point the Justice Department is explicit about: QTFY is described as a contractor, not an arm of Chinese intelligence, whose most notable client happened to be the Ministry of State Security. The same botnet infrastructure would presumably have been available to any customer able to pay.

Seizing three domains removes QTFY’s current command infrastructure but does nothing for the IoT devices already infected and still listening for QTRouter traffic; those need patching or replacement by their owners, not law enforcement. Worth watching is whether CISA follows with an advisory naming the affected device models, and whether the seizure is followed by unsealed criminal charges against the Nanjing Xinjiuwei Network Technology Company or named individuals, something that has not happened yet.

Tags: chinavulnerability
Previous Post

Ubisoft announces turn-based Rainbow Six Tactics for 2027

Next Post

Geoff Keighley hosts Gamescom 2026, Witcher 3 remaster revealed

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

October 1, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Close-up of steel plate armor gauntlets gripping a sword hilt against the chest

Geoff Keighley hosts Gamescom 2026, Witcher 3 remaster revealed

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply