China-Linked Hackers Spent Years Inside NASA, the Fed and the Senate Before the FBI Shut Them Down
Federal operation disrupts sophisticated Chinese hacking infrastructure targeting US institutions

Federal officials in the United States say they have dismantled a long‑running cyber‑espionage operation in which China‑linked hackers allegedly penetrated or targeted some of Washington's most sensitive institutions, including NASA, the Federal Reserve and the Senate.
According to court filings unsealed on 26 August in California, the inter‑agency operation seized key internet domains that Chinese operatives allegedly relied on to run surveillance campaigns against critical American institutions.
How China-Linked Hackers Co-Opted Global Consumer Technology
The campaign operated through a commercial front that systematically co‑opted compromised internet‑of‑things (IoT) devices to try to infiltrate government systems across the United States over an extended period.
While attackers successfully compromised several networks, official records state that intrusion attempts against others, such as the Department of Energy and NASA, were stopped before hackers could gain access.
Documents unsealed in the Southern District of California state that a state‑sponsored hacking collective known as QTFY orchestrated the multi‑year espionage campaign under the corporate name Nanjing Xinjiuwei Network Technology Company.
The mainland company developed and ran two custom software platforms, called QScan and QTRouter, which worked together to compromise target systems across the United States.
According to federal investigators, QScan automatically identified and infected thousands of vulnerable IoT devices around the world.
Once compromised, these household and office devices were absorbed into the QTRouter network, forming a large botnet that routed commands while masking the alleged Chinese government origins of the activity from US network defenders.
Federal prosecutors said the private contractor operated as a commercial hacking service for state clients in Beijing.
Court filings indicate that QTFY regularly sold its technical tools and access points to China's Ministry of State Security and the People's Liberation Army, an organisation with one of the most capable military cyber commands in the world.
Federal Enforcement Action Cripples China-Linked Hackers' Botnet
The court‑authorised domain seizures carried out by federal law enforcement made both QScan and QTRouter inoperable, removing the primary infrastructure used to conceal state‑directed intrusions.
The disruption is part of an ongoing federal effort to directly dismantle adversary infrastructure and neutralise foreign cyber threats before intelligence can be stolen.
Attorney General Todd Blanche said that federal law enforcement intervened to disable the software, and said state‑sponsored actors targeting American critical infrastructure will be pursued and prosecuted.
Blanche said that the technical operation neutralised the programmes, describing the seizure as part of a continuing effort to break up hacking operations sponsored by the People's Republic of China.
FBI Director Kash Patel highlighted the bureau's role in taking down what he described as a global botnet and hacking platform used against essential infrastructure.
Patel said that federal investigators are increasing operational pressure to influence adversary behaviour and defend domestic networks, carrying out technical disruptions aligned with national cyber defence priorities.
The Chinese government has repeatedly denied involvement in state‑directed hacking, rejecting allegations from Western security agencies as politically motivated.
While the Chinese Embassy in Washington says Beijing opposes all forms of cybercrime, American officials say commercial cut‑outs provide the Chinese government with deniability while carrying out surveillance.
Whether this takedown permanently stops the contractor's activities is unclear, given how quickly some Chinese private contractors have previously rebranded and rebuilt disrupted platforms. For American network administrators, the campaign underlines continuing vulnerabilities in critical public infrastructure.
© Copyright IBTimes 2026. All rights reserved.
























