FBI takes down domains used by Chinese state-sponsored hackers in U.S. agency intrusions
The U.S. Justice Department and FBI have seized domains linked to a Chinese state-sponsored hacking group called QTFY. The group allegedly used malware to compromise systems at NASA, the Senate, the Federal Reserve, and other agencies. The seizures are part of an ongoing investigation that dates back to 2018.
The seized domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—were registered between 2022 and 2024 via Namecheap and paid for through PayPal, according to the FBI. Investigators first traced the hacking operation to a 2019 NASA intrusion exploiting CVE-2019-11510, linking activity to Gmail accounts and a Chinese phone number. The malware QScan reportedly automates infection of IoT devices, building a botnet that masks malicious traffic. The Justice Department alleges the group operated under Nanjing Xinjiuwei Network Technology Company, though no public records were found for that firm.
This action may signal a more assertive U.S. posture against state-sponsored cyber operations, potentially deterring similar attacks but also straining diplomatic relations. Federal agencies and critical infrastructure operators could face heightened scrutiny of their defenses, while private companies hosting or registering domains may need to strengthen abuse monitoring. The public may gain greater awareness of persistent cyber threats, though the long-term effectiveness of domain seizures in disrupting sophisticated state actors remains uncertain.