US seizes Chinese hacking tools after alleged Federal Reserve breach, DOJ announces

1 hour ago 22

The US Department of Justice and the FBI announced the seizure of two hacking platforms tied to a Chinese state-sponsored cyber group that allegedly breached some of the most sensitive institutions in the country, including the Federal Reserve.

The platforms, known as QScan and QTRouter, were attributed to a group called QTFY, which the US government linked to the Nanjing Xinjiuwei Network Technology Company. The tools reportedly allowed hackers to mask their origins while penetrating targets across the federal government and critical infrastructure sectors.

What was breached and how it worked

The list of named victims includes the Federal Reserve, NASA, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The affected targets also spanned critical infrastructure sectors including telecommunications providers, hospitals, and financial institutions.

QScan and QTRouter functioned as obfuscation tools, letting attackers route their intrusions through layers of misdirection so that tracing the source became exponentially harder.

The seizure of these platforms on August 26 represents part of a broader, ongoing US campaign against PRC-sponsored cyber operations.

The Federal Reserve angle

The Federal Reserve’s inclusion on the victim list is notable given prior documented targeting of the institution. A 2022 report from the Senate Homeland Security Committee revealed ongoing Chinese recruitment efforts targeting personnel at the Federal Reserve, known as the ‘P-Network.’ In January 2025, a senior adviser at the Federal Reserve was indicted on charges related to economic espionage, reaffirming the depth of collaboration between individuals and Chinese state actors.

Details remain sparse regarding the extent of the breaches, particularly in relation to sensitive policy data from the Federal Reserve.

The bigger picture on PRC cyber operations

What makes this case notable is the breadth of the target list and the specificity of the attribution. Naming the Nanjing Xinjiuwei Network Technology Company and the QTFY group signals that US intelligence has enough confidence in its evidence to go public.

The seizure of QScan and QTRouter disrupts the operational toolkit available to the group, at least temporarily. Cyber actors can rebuild, but losing established infrastructure forces them to start over, introducing delays and potential exposure during the reconstruction period.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article