The victim list reads like a hostile nation’s wish list: the Federal Reserve, NASA, the DOJ itself, the U.S. Senate, the Department of Energy, HHS, NIH. Add hospitals, telecom providers, power companies, and defense contractors. According to court documents unsealed August 26, 2026, in the Southern District of California, a Chinese state-sponsored group called QTFY — employed by Nanjing Xinjiuwei Network Technology Company — had conducted computer intrusion activity targeting all of them.
Your Smart Devices Were the Weapon
The operational architecture QTFY built is what distinguishes this breach from routine espionage.
QTFY didn’t hack targets directly. They built a two-stage industrial operation. QScan automatically infected thousands of IoT devices worldwide — routers, cameras, smart home hardware — conscripting them into a network called QTRouter. That network, padded with commercial proxy services and leased virtual private servers, masked all malicious traffic to look like it originated nowhere near China. Think of it as the hacking equivalent of routing a wire transfer through seventeen shell companies. The paying customers for this service? According to DOJ filings: the PRC Ministry of State Security and the People’s Liberation Army.
What the court documents confirm:
- QScan infected IoT devices at scale; QTRouter wove them into an obfuscation layer hiding the PRC origin of intrusions
- QTFY’s employer, Nanjing Xinjiuwei, operated as a commercial front packaging state hacking as a service
- The MSS and PLA were paying customers — contracting out espionage the way enterprises contract out cloud storage
- DOJ disabled both platforms by seizing hard-coded domains the malware needed to communicate and authenticate
- What the DOJ has not disclosed: what data left, what systems were compromised, how long access persisted
One Court Order, Many Open Questions
The disruption was legally clean — what comes next is anything but.
The takedown itself was precise. Both platforms had specific domains baked into the malware’s code. Seize those domains — which DOJ did via court order — and QScan and QTRouter stop functioning entirely.
What remains murky is everything downstream. The DOJ’s framing pledges to “dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” but says nothing about what QTFY actually took from the Federal Reserve, NASA, or the Senate. A Chinese embassy spokesperson, responding to a related June 2026 domain seizure, dismissed U.S. accusations as “fabricated and malicious slander,” per Reuters — a denial that is consistent with Beijing’s standard posture, though it resolves nothing factually. The use of a covert surveillance app by state actors further underscores how digital operations increasingly blur the line between espionage and infrastructure attacks.
The announcement arrived roughly a month after former Federal Reserve senior adviser John Harold Rogers was sentenced to 38 months in prison for making false statements about sharing FOMC information with Chinese intelligence operatives — a separate case, same strategic backdrop. Technical intrusion and human intelligence, running on parallel tracks. The platforms are down. Public documents do not disclose the damage.





























