China Hackers Busted — Core Systems Probed

CHINA HACKERS BUSTED

The FBI says a China-backed hacking crew quietly probed America’s core systems for years—and the government just yanked key tools out of their hands.

Story Snapshot

  • Justice Department and FBI seized platforms tied to China-linked hackers targeting U.S. critical infrastructure.
  • Court records and a Defense advisory link the group, called QTFY, to wide scans and intrusions since 2018.
  • Targets included the Justice Department, NASA, the Federal Reserve, and the U.S. Senate, among others.
  • China’s embassy denies support for hacking and calls such claims smears.

What Authorities Say Was Hit And How

The Justice Department and the Federal Bureau of Investigation announced the seizure of internet platforms tied to a China-backed hacking group that probed critical U.S. networks, from federal agencies to key infrastructure.

Court documents and federal statements describe a campaign that targeted the Justice Department, the National Aeronautics and Space Administration, the Federal Reserve, and the United States Senate, as well as health and energy targets.

Officials say the hackers used custom tools to hide their tracks and route attack traffic through layers of compromised systems.

Defense and intelligence partners published a detailed advisory on the group, known as QTFY, and link it to a China-based company.

The advisory says QTFY’s tools, including a scanner dubbed QScan and a traffic router, helped operators mask their location while probing defense, communications, government, and higher education networks.

The document cites specific scans and attempts against a U.S. state government, a water district, the U.S. Senate, a hospital system, and an election system in 2026, matching the pattern seen in recent court filings.

The Tools And Tactics That Kept Them Hiding

Investigators describe a “malicious distributed system” model. The hackers first built or rented large pools of internet-connected devices.

They then pushed traffic through those devices to scan, test, and sometimes break into targets while hiding the true source.

The court records referenced by major outlets add that the group sold access to these services, giving state customers a ready-made way to find weak spots and move in quietly, including at energy labs and health agencies in 2024.

Law enforcement moved to cut off that reach by seizing domains and related infrastructure. Removing the platforms forces attackers to rebuild, lose cover, and risk exposure. It also lets defenders map victims who saw traffic from those systems.

This playbook—public attribution, technical advisories, and asset seizures—has become a standard way to raise the price of hostile cyber activity and warn likely targets to harden their systems.

Beijing’s Denial And What To Make Of It

The Chinese embassy in Washington rejects the claims and says China opposes all cyberattacks. The embassy urged the United States to stop using cybersecurity to smear China.

That stance mirrors past statements where Chinese officials branded similar allegations “baseless slanders” in other cases abroad.

Diplomatic denials are expected. They matter less than the weight of technical reporting, sworn affidavits, and coordinated action across agencies, which here point in the same direction.

On one side, the United States put specifics on the table: named targets, tool descriptions, dates, and a domain seizure that ends real-world access.

On the other, broad denials without matching technical detail. That asymmetry argues for taking the government’s claims seriously while still pressing for stronger network defense, faster patching of known flaws, and tighter vendor controls.

Why This Hits Home For Every American

Government networks guard everything from court records to space data. Health and energy systems keep hospitals running and the lights on.

When an adversary maps those systems, it gains options in a crisis. The advisory lists scans against an election system and attacks on water and defense targets. That should focus minds.

Elections, utilities, and contractors run on old software and busy crews. Small fixes—multi-factor logins, network segmentation, offline backups—block big problems.

Policymakers should couple public exposure with teeth. Tie future seizures to fast sanctions on front companies. Fund state and local agencies to replace end-of-life gear. Require vendors to ship secure defaults and quick patches.

Expand threat sharing that tells defenders not just what to fear, but what to block today. The pattern is clear and ongoing. The window to harden before the next campaign is open now. Close it.

Sources:

nypost.com, cnbc.com, media.defense.gov, berndpulch.org, reuters.com, justice.gov, nextgov.com