The US just seized the servers behind China's hacking-for-hire empire
A private Chinese company quietly ran shared attack tools for state hackers targeting NASA, the Federal Reserve, and US hospitals. The FBI just pulled the plug.

Key points
- The US Justice Department and FBI seized internet domains belonging to a Chinese hacking-services company called Nanjing Xinjiuwei Network Technology in an operation announced last week.
- The company's tools, called QScan and QTRouter, infected thousands of everyday devices worldwide and used them to hide attack traffic routed through more than 130 countries.
- Confirmed targets include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, and major US hospital systems.
- Nanjing Xinjiuwei's paying clients included China's Ministry of State Security and units of the People's Liberation Army.
- Experts warn that similar contractor companies will likely fill the gap left behind.
A private company in Nanjing, China built a subscription service for state-sponsored hackers. Its clients: China's spy agency and military. Its targets: some of the most sensitive networks in the United States. Last week, the FBI and Department of Justice cut it off at the knees.
The company, Nanjing Xinjiuwei Network Technology, operated under a hacking group researchers tracked as QTFY. It sold two tools. QScan automatically found and silently infected thousands of internet-of-things (IoT) devices worldwide, things like home routers and security cameras, without their owners knowing. QTRouter then wove those hijacked devices into a private relay network, meaning traffic from Chinese state hackers appeared to originate from ordinary homes and businesses in dozens of countries rather than from China itself.
"Instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries, potentially through systems just down the street from the victim's own network," FBI cyber assistant director Brett Leatherman said.
What did the hackers actually do with this?
For nearly a decade, QTFY gave paying clients a ready-made attack pipeline. Clients could scan for targets, break in, and cover their tracks, all through shared infrastructure they did not have to build themselves.
Targets identified by the FBI included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. Power companies, telecoms, and hospital systems were also hit.
Lumen's Black Lotus Labs spent a year tracking the operation before the takedown. Researchers there described the company's role as that of a "quartermaster", a military supply term for someone who equips the troops. Nanjing Xinjiuwei did not always conduct the break-ins itself. It sold the tools and the hiding infrastructure so that multiple separate hacking teams could run their own operations through one shared network.
"It's kind of like a choke point," said Dakota Cary, a China-focused analyst at the security firm SentinelOne, speaking to CSO Online. "You have a bunch of teams using the same network to carry out offensive operations. If you take down that network, they all have to go find new infrastructure."
Why does China use private companies for this?
Beijing gets two things from outsourcing: capacity and deniability. Private contractors, often founded by people who left the People's Liberation Army, do the work at arm's length from the government.
"It gives the government plausible deniability because it's not actually coming from their units," said Damon Rouse, senior security engineer at Black Lotus Labs. The FBI tracked payments from PLA and Ministry of State Security units directly to Nanjing Xinjiuwei, helping expose the client list.
This is not the first time US law enforcement has dismantled Chinese hacking infrastructure. In 2024 the FBI shut down a botnet, a network of hijacked devices, run by the group known as Flax Typhoon (Microsoft's naming convention). In 2023 it disrupted a different botnet tied to the group called Volt Typhoon (also Microsoft's label), which hid inside US critical infrastructure. The group Mustang Panda (tracked by multiple vendors including CrowdStrike) had surveillance software removed from more than 4,000 US computers in a separate action.
Should ordinary people be worried?
The primary targets here are government agencies and large organisations, not individual consumers. But the attack traffic passed through ordinary home routers and IoT gadgets that real people own.
If you have a home router, a smart camera, or any device that connects to the internet, keeping its software up to date is the single most useful thing you can do. Manufacturers regularly release updates that close the security holes these kinds of operations exploit. Replacing old devices that no longer receive updates is worth considering too.
Experts also warn that geography-based blocking, security tools that flag traffic because it originates from a suspicious country, no longer works reliably against this kind of operation. Chinese state hacking traffic looked like it came from Charter Communications addresses inside the United States. Organisations need tools that watch for unusual behaviour, not just unusual origins.
| Event | Group (vendor label) | Year |
|---|---|---|
| PlugX malware removed from 4,000+ US computers | Mustang Panda (multiple vendors) | 2024 |
| IoT botnet dismantled | Flax Typhoon (Microsoft) | 2024 |
| Critical-infrastructure botnet disrupted | Volt Typhoon (Microsoft) | 2023 |
| QScan/QTRouter domains seized | QTFY / Nanjing Xinjiuwei | 2025 |
Analysts are clear-eyed about what the seizure does and does not achieve. "It would be naive to say there's not going to be another company or another 10 companies doing something very similar," Rouse said. Chinese cybersecurity firm Chengdu 404, indicted years ago as a front for the group tracked as APT41, still operates from the same address. Nanjing Xinjiuwei could do the same. The disruption forces a scramble. It does not end the game.



