- October 2, 2026
- Updated 1:12 am
Chinese Hacking Operations Target U.S. Infrastructure
- 29 Views
- admin
- August 27, 2026
- Technology
Cyber Infiltration Blocked by Justice Department
The Department of Justice recently thwarted a cyber infiltration by Chinese hacking operations targeting critical U.S. infrastructure. These operations posed a significant national security threat, and were analyzed by Bret Baier and the ‘Special Report’ All-Star Panel.
Chinese state-linked hackers allegedly stole sensitive data from over 300 organizations, including U.S. defense contractors, financial institutions, and universities. They breached three Energy Department laboratories, the NIH, and a Health and Human Services agency before the FBI disabled their hacking platforms this week, as revealed by newly unsealed court records.
Identified as QTFY, these hackers operated through a China-based company that the FBI reports sold hacking services to clients such as China’s Ministry of State Security and People’s Liberation Army. Former PLA members participated in this company, utilizing military connections to secure offensive cyber operation contracts and subcontracts, according to an FBI affidavit.
Methods Employed in Cyber Attacks
QTFY employed mass internet scanning paired with a network of compromised routers, cameras, and other internet-connected devices to disguise the origin of their attacks. By directing malicious traffic through devices near a victim’s network, the hackers made their attacks blend in with legitimate local traffic, complicating detection and tracing, federal officials noted.
Seizures and Impact of FBI Actions
On Wednesday, the Justice Department and FBI seized three domains powering QTFY’s two main platforms: QScan and QTRouter. QScan searched for vulnerable systems, while QTRouter masked hacker identities via compromised device traffic routing. The seizures crippled both platforms by cutting off domains critical for their communications and authentication.
The magnitude of operations was substantial. On a single day in 2024, QScan processed more than 2 million scanning and penetration-testing tasks, per the FBI affidavit. The platform contained over 200 proof-of-concept exploits and canvassed the internet for software vulnerabilities, exposed services, and other exploitable openings.
Targeted Organizations and Failed Attempts
QTFY targeted numerous entities, including NASA, the Justice Department, the Federal Reserve, Senate systems, power companies, hospitals, telecommunications providers, defense contractors, and election infrastructure.
Not all attacks succeeded, however. For instance, in 2019, QTFY attempted to infiltrate NASA using a vulnerability in its virtual private network but failed because NASA had already patched the flaw, according to the affidavit. A separate advisory stated that the group scanned Senate and hospital-system networks in March and a U.S. election system in June but did not gain access.
Successful Breaches and Undisclosed Information
Some attacks did succeed, notably in May 2024, when hackers exploited a Check Point vulnerability to steal data from over 300 organizations globally, as reported in the advisory. Victims included U.S. defense contractors, financial institutions, and universities, although specific organizations and stolen information remain unidentified.
Four months later, zero-day flaws in Ivanti Cloud Services Appliance software allowed hackers to access three Department of Energy national laboratories, the National Institutes of Health, the Health Resources and Services Administration, and a U.S. security-device manufacturer, the advisory highlighted. Details on the accessed data and the duration of hacker presence remain undisclosed.
Ongoing Efforts Against State-Sponsored Cyber Threats
Attorney General Todd Blanche emphasized commitment to stopping and prosecuting state-sponsored hackers targeting America’s critical infrastructure. The recent takedown adds to a series of FBI operations dismantling infrastructure utilized by Chinese government-linked hacking groups.
Past efforts include the disruption of a botnet used by Volt Typhoon and dismantling another provided by Flax Typhoon, alongside removing PlugX surveillance malware from over 4,000 U.S. computers infected by Mustang Panda, another China-linked group.
Recent Posts
- Political Analysts Discuss Election Security and Voting Decisions
- Calls to Commute Sentence for Christa Pike After Failed Execution
- Supreme Court to Review Detention Policy, British-Iranian Arrest, Drone Attacks in Kyiv
- Trump Team Targets U.S. Military Leadership
- Massachusetts Judge Allows Murder Case Against Lindsay Clancy to Proceed