Twikup logo
Twikup
US Revises China Hacking Claims, Says Agencies Were Targets

US Revises China Hacking Claims, Says Agencies Were Targets

By Akshay SatijaEditor in ChiefAugust 29, 2026Updated August 29, 20265 min readAug 29, 2026#QTFY#China Hacking#China Cyberattack#Cybersecurity#US Cybersecurity

TwikUp Brief

Three things to know

  1. 01

    The DOJ says the U.S. Senate, Federal Reserve, NASA, Department of Energy, DOJ, HHS and NIH were among QTFY's targets.

  2. 02

    Being identified as a target does not necessarily mean an organization was successfully breached.

  3. 03

    The FBI and NSA say QTFY has operated since at least 2018 and used platforms including QScan and QTRouter to conduct reconnaissance, exploit vulnerabilities and conceal the origin of cyber activity.

In this article · 10 sections

Targeted Does Not Mean Successfully Hacked

The distinction between being targeted and being successfully breached is important.

A cyber threat actor can attempt to compromise a network without gaining access to it.

The updated DOJ wording is intended to make that distinction clearer and accurately reflect the allegations contained in the FBI affidavit.

Some organizations were targeted but the attempts were not necessarily successful, while the affidavit describes successful intrusions involving other U.S. government-related systems.

What Is QTFY?

QTFY is a China-linked cyber threat group that U.S. authorities say has been active since at least 2018.

The FBI and National Security Agency say the group developed malicious tools and operated through networks designed to conceal the origin of cyber intrusions.

The agencies say QTFY has targeted organizations in multiple sectors, including critical infrastructure, telecommunications, government and higher education.

How Did QTFY Operate?

According to U.S. authorities, QTFY developed several interconnected platforms.

One of them, known as QScan, was used to scan networks and exploit vulnerable Internet of Things devices.

Another platform, QTRouter, was used as an obfuscation network.

The system could route malicious communications through compromised devices and other infrastructure, making the activity appear to originate outside China.

U.S. Government Agencies Were Among the Targets

The revised DOJ statement identifies several major U.S. government organizations among QTFY's targets.

These include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.

The wording does not mean that every organization listed was successfully compromised.

That distinction is central to the updated U.S. government statement.

Why Did the DOJ Change Its Statement?

The Department of Justice said edits were made to ensure that its press release accurately reflected the government's allegations in the FBI affidavit supporting the domain seizures.

The updated language therefore focuses on organizations being targeted rather than broadly describing them as victims.

The change highlights the difference between attempted cyber intrusions and confirmed successful breaches.

What Happened to QScan and QTRouter?

The Justice Department and FBI obtained court authorization to seize domains used by the QScan and QTRouter platforms.

According to the DOJ, the seized domains were hard-coded into the malware and were required for important communication and authentication functions.

The domain seizures therefore made the two platforms inoperable.

U.S. Agencies Disrupt the Infrastructure

The operation was led by the FBI and Justice Department, with support from federal cybersecurity and national-security teams.

The agencies said the action was intended to disrupt infrastructure used by China-linked cyber actors and prevent continued use of the platforms against U.S. and foreign networks.

What Does This Mean for Cybersecurity?

The case shows how modern cyber campaigns can use compromised devices and proxy infrastructure to hide the origin of attacks.

Instead of communicating directly with a target from infrastructure controlled in China, attackers can route activity through devices and servers located elsewhere.

That makes attribution and detection more difficult for organizations trying to defend their networks.

FBI and NSA Issue Security Guidance

The FBI and NSA have also released technical guidance based on their analysis of QTFY activity.

The agencies recommend that organizations keep software and firmware updated, audit internet-facing applications, isolate critical systems from edge devices and monitor for indicators associated with QTFY activity.

The guidance is intended to help organizations identify and reduce the risk associated with the group's techniques.

The Bigger Picture

The latest development is not simply a reversal of the U.S. government's assessment of QTFY.

Instead, the DOJ's update clarifies how the government is characterizing the relationship between the hacking group and the organizations named in its investigation.

Some organizations were targets of attempted activity, while the FBI affidavit describes successful intrusions involving other systems.

The distinction matters because saying an organization was targeted is not the same as saying its network was successfully breached.

TwikUp Insight

The U.S. Department of Justice has revised its description of the QTFY cyber campaign, clarifying that NASA, the Federal Reserve, the U.S. Senate and several other government agencies were among the group's targets.

The DOJ says the update was made to accurately reflect allegations in the FBI affidavit.

The case also highlights the growing use of compromised IoT devices and proxy networks to conceal the origin of state-linked cyber activity.

DOJ Clarifies Hacking Claims

The U.S. Department of Justice has updated its August 26 cybercrime announcement to clarify that several U.S. government agencies were among the targets of QTFY activity. The department said the edits were made to ensure the release accurately reflected allegations contained in an FBI affidavit.

Verified reading

Sources & References

Open the original material in a new tab.

Frequently Asked Questions

FAQ

Did Chinese hackers successfully hack NASA?

The updated DOJ statement identifies NASA as one of QTFY's targets. Being listed as a target does not, by itself, establish that NASA was successfully breached.

Which U.S. government agencies were targeted by QTFY?

The DOJ identifies NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate among QTFY's targets.

What is QTFY?

QTFY is a China-linked cyber threat group that U.S. authorities say has operated since at least 2018 and developed tools for reconnaissance, exploitation and cyber-intrusion operations.

What are QScan and QTRouter?

QScan and QTRouter are two platforms that U.S. authorities say were operated by QTFY. QScan was used for scanning and exploiting vulnerable IoT devices, while QTRouter functioned as an obfuscation network designed to conceal the origin of cyber activity.

Why did the DOJ revise its statement?

The DOJ said it updated the August 26 release so that it accurately reflected the government's allegations contained in the FBI affidavit supporting the domain seizures.