Eight-year cyber-espionage campaign penetrated the Federal Reserve, Justice and Energy departments, NASA, and the US Senate before the FBI seized its enabling infrastructure.
Intelligence Lead
The Justice Department and FBI announced Wednesday the seizure of two hacking platforms, QScan and QTRouter, that Chinese state-sponsored operators used to breach a sweeping list of US government and critical-infrastructure targets since 2018. Unsealed affidavits identify the Federal Reserve, NASA, the Departments of Justice and Energy, the US Senate, national laboratories, hospitals, and defense contractors as confirmed victims. The disclosure marks one of the largest publicly documented Chinese cyber-espionage operations against US federal institutions to date.
Situation Report
According to an FBI agent's affidavit filed in support of the domain seizures, a threat actor tracked internally as QTFY built and operated QScan and QTRouter as dual-use platforms: QScan for reconnaissance and vulnerability mapping of internet-connected devices, and QTRouter for compromising routers and other network hardware to conceal the origin of intrusions. Assessed with high confidence to be linked to China's military and intelligence services, the operators are reported to have contracted Nanjing Xinjiuwei Network Technology Company, a China-based firm, to develop and run elements of the toolset — a cutout arrangement consistent with Beijing's established pattern of using nominally private contractors to obscure state direction.
Confirmed victims span an unusually broad cross-section of US institutions: the Federal Reserve and Department of Justice at the center of financial and legal policy, NASA and Department of Energy national laboratories at the center of advanced technology, and the US Senate at the center of legislative deliberation. The affidavit additionally names the National Institutes of Health, a Department of Health and Human Services component, hospitals, telecommunications providers, and power utilities among affected networks. Reported intrusion activity dates to 2018 and continued into 2026, indicating sustained, long-term access rather than a single breach event.
The Justice Department's action seized the domains underpinning both platforms, degrading the operators' ability to launch further intrusions through that specific infrastructure. No individual indictments accompanied Wednesday's announcement; officials described the seizure as a disruption operation rather than a completed prosecution.
Background & Context
The QScan/QTRouter disclosure lands amid a run of Chinese state-linked cyber operations exposed against US targets over the past two years, including the Salt Typhoon intrusions into telecommunications carriers' call data and lawful-intercept systems, and the 2024 compromise of Treasury Department workstations. Each case has followed a similar pattern: long-dwell-time access into sensitive networks, use of compromised edge devices such as routers to mask origin, and reliance on ostensibly commercial Chinese technology firms as operational fronts.
The targeting of the Federal Reserve and Senate networks specifically extends Chinese cyber-espionage priorities beyond the defense and telecommunications sectors historically associated with Salt Typhoon and related campaigns, into monetary policy deliberation and legislative process — domains with direct bearing on economic statecraft and policy forecasting.
Analysis & Assessment
The eight-year operational window assessed in the affidavit suggests the compromised networks may have yielded sustained collection against Federal Reserve policy deliberations and Senate legislative activity, rather than a discrete data-theft event. Analysts should treat the full scope of exfiltrated material as unresolved pending further disclosure; a platform seizure closes one avenue of access but does not by itself confirm remediation of every compromised network named in the affidavit.
Beijing is likely to issue a standard denial characterizing the allegations as fabricated or politically motivated, consistent with its response to prior US attribution of Salt Typhoon and Treasury-related intrusions. The absence of named individual defendants leaves open whether the Justice Department is preparing a sealed indictment for later unsealing, a pattern used in past China-attributed cyber cases to allow continued intelligence collection before prosecution becomes public.
The scale of institutions named, particularly the Federal Reserve and Senate, raises the probability of congressional hearings and classified briefings in the coming weeks, and increases pressure on affected agencies to disclose remediation timelines.
