Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
DOJ Seizes Domains Used by Chinese State Hackers Who Breached Fed, NASA, Senate, DOJ

The Justice Department announced Wednesday it seized internet domains tied to two Chinese state-sponsored hacking platforms that breached the Federal Reserve, NASA, the DOJ, the U.S. Senate, and several other federal agencies.
The platforms, called QScan and QTRouter, were used to compromise networks belonging to the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health, according to court documents unsealed in the U.S. District Court for the Southern District of California. An FBI affidavit also named four unnamed companies in the U.S. and South Korea as victims, according to Reuters reporting carried by Global News and The Independent.
The intrusions weren't limited to government targets. Court filings say the platforms hit hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The FBI says the campaign has been running since at least 2018.
How the hacking network worked
According to the affidavit, QScan scanned the internet for vulnerable internet-of-things devices and automatically infected thousands of them worldwide. Those compromised devices then fed into QTRouter, a network that let hackers hide the true origin of their attacks by routing malicious traffic through infected devices located near their actual targets. This made intrusions look like they came from ordinary local users.
The FBI says it investigated an attempted QTFY intrusion into NASA's network in 2019, but that attempt failed because NASA had already patched the vulnerability the hackers were trying to exploit, according to Anadolu Agency.
Authorities attribute the platforms to a Chinese state-sponsored group called QTFY, which the DOJ says was employed by Nanjing Xinjiuwei Network Technology Company, a China-based firm. Court documents say QTFY's paying customers included China's Ministry of State Security and the People's Liberation Army. Neither CNBC nor USA TODAY, via AOL, could locate contact information for Nanjing Xinjiuwei.
Deputy Attorney General Todd Blanche said in a statement that "state-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted." FBI Director Kash Patel called the action the disruption of "a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," tying the operation to what he described as President Trump's Cyber Strategy for America.
By seizing the domains hard-coded into the QScan and QTRouter malware, the DOJ says it rendered both platforms inoperable. The FBI and NSA also issued a joint cybersecurity advisory on QTFY activity dating back to 2018, according to Anadolu Agency.
A separate, broader indictment
Alongside the domain seizure, the DOJ unsealed indictments against 12 Chinese nationals in a separate but related hackers-for-hire conspiracy, according to Breitbart. That case accuses China's Ministry of Public Security and Ministry of State Security of directing and financing hackers to target U.S.-based critics and dissidents of the Chinese Communist Party, a large U.S. religious organization, foreign ministries in Asia, and U.S. federal and state agencies as recently as 2024.
Two of the defendants, Yin Kecheng and Zhou Shuai, are allegedly linked to APT27, also known as "LuckyMouse" or "Emissary Panda," a group active since 2010. DOJ says the pair inflicted "millions of dollars worth of damages" through hacking conspiracies dating back to 2011.
The indictment also names two Ministry of Public Security officers and eight employees of Anxun Information Technology, known as i-Soon, which DOJ says generated tens of millions of dollars in revenue as a hacker-for-hire operation. According to the indictment, i-Soon billed Chinese intelligence agencies between $10,000 and $75,000 for each email inbox it penetrated, and separately sold stolen data to at least 43 bureaus across 31 Chinese provinces and municipalities on its own initiative.
What's unproven, and what's next
Beijing has not been charged in any court and consistently denies state involvement in hacking campaigns, a position the Chinese Embassy in Washington reiterated to reporters in the past. The embassy did not immediately respond to requests for comment from The Independent, Global News, or CNBC on this specific case. None of the named defendants are in U.S. custody, and no trial dates have been set. Indictments are allegations, not convictions.
Dakota Cary, a China analyst with cybersecurity firm SentinelOne, told The Independent and Global News that private contractors routinely carry out high-profile intrusions on behalf of Chinese government agencies, and that "the number of companies offering niche offensive services has exploded" over the last decade. This dynamic lets Beijing outsource espionage while maintaining deniability.
The domain seizures disable the specific QScan and QTRouter infrastructure identified in this case. They do not, on their own, stop QTFY or similar contractors from standing up new platforms, and the DOJ has not said whether it expects further indictments tied to the broader hacker-for-hire ecosystem it describes.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.