NEWS
DOJ Edit Narrows China Hack Victims but Confirms Lab Breaches
US officials corrected the QTFY press release so Senate, Fed and NASA are targets not victims, while affidavit still lists DOE lab and NIH intrusions from 2024.
The Justice Department rewrote its August 26 press release on Friday so that the U.S. Senate, Federal Reserve, NASA and several other agencies are described as “among the targets” of the Chinese-linked group QTFY rather than victims. The change followed the original wording that treated the entire list as compromised.
A note at the bottom of the updated release states that the edits ensure the text “accurately reflects the government’s allegations in the affidavit in support of the domain seizures.” The DOJ explained that the first version “described all agencies as victims whereas the government’s affidavit made clear that all were targeted but only some were compromised.”
The revision does not walk back the broader campaign narrative. It narrows only the claim of confirmed compromise for the highest-profile names that appeared in the first public list.
What the Wording Shift Changed
The distinction shrinks the roster of confirmed breaches inside a campaign the government still calls years-long Chinese cyber-espionage against federal networks, defense contractors and other sensitive targets. According to the FBI affidavit released with the original announcement, the group has targeted U.S. federal networks since at least 2018. The list includes NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.
A footnote in that affidavit records that the FBI investigated the NASA targeting and found the attempted breach unsuccessful because the agency had patched the software in question. By contrast, the same document alleges that in September 2024 the hackers carried out computer intrusions at three DOE National Laboratories, NIH, an HHS agency and a U.S. security-device manufacturer, and it calls those entities victims.
- Original release language: agencies listed as victims of QTFY
- Edited release language: agencies listed as among the targets
- Affidavit baseline: all targeted, only some compromised
- Confirmed 2024 intrusions: three DOE labs, NIH, HHS agency, security-device maker
The correction therefore leaves the successful lab and health-agency breaches intact while removing the implication that every high-profile name on the original list suffered the same fate.
That split matters for how the case is read outside the courtroom. Targeting evidence still supports the multi-year espionage framing. Confirmed-compromise language is now reserved for the entities the affidavit names as victims. Readers who saw only the first headlines encountered a wider breach picture than the sworn filing supports.
The affidavit’s own footnote on NASA supplies the clearest example of the line the department is now drawing in public. An attempted Pulse Secure VPN exploit reached the agency. Patching stopped it. The Senate and Federal Reserve remain on the target list without a matching public finding of successful intrusion in the materials released so far.

How the QScan and QTRouter Platforms Worked
On August 26 the Justice Department and FBI announced court-authorized domain seizures of QScan and QTRouter. Those two complementary platforms were operated by QTFY, which the government links to the China-based Nanjing Xinjiuwei Network Technology Company. The firm’s clients allegedly include the Ministry of State Security and the People’s Liberation Army.
QScan scans and automatically infects thousands of internet-of-things devices worldwide. Those devices, along with commercial proxy services and leased virtual private servers, feed into QTRouter. The router network then functions as an obfuscation layer so that malicious traffic appears to originate outside China and sometimes near the target networks. Because the seized domains were hard-coded into both pieces of malware for communication and authentication, the seizures rendered the platforms inoperable.
The hard-coded domain design made the court order decisive. Once the domains went offline, the malware lost its built-in path for command traffic and authentication checks. Operators could not simply point the same implants at a new address without rebuilding and redeploying the tooling.
Attorney General Todd Blanche said state-sponsored hackers preying on critical infrastructure “will be stopped and prosecuted.” FBI Director Kash Patel called the action a disruption of a global botnet and hacking platform used by Chinese state-sponsored actors.
Taken together, the two statements frame the seizures as both a technical cut and a prosecutorial warning. The inoperable platforms remove a working enablement layer. The public language keeps the focus on state-sponsored use of that layer against critical infrastructure.
Confirmed Breaches and Failed Probes Across Eight Years
A joint cybersecurity advisory on QTFY tactics issued the same day by the FBI, NSA and U.S. Cyber Command’s Cyber National Mission Force supplies a detailed activity sample. The timeline stretches from 2018 vulnerability scans through 2026 election-system probes.
| Date | Activity | Outcome |
|---|---|---|
| May 2018 | Vulnerability scanning | Early observed activity |
| August 2019 | Pulse Secure VPN exploit against DOJ, Fed, NASA | NASA attempt failed after patching |
| May 2024 | QScan plus Check Point exploit | Data exfiltrated from 300+ organizations including defense contractors, financial institutions, universities |
| September 2024 | Zero-day Ivanti CSA exploits | Intrusions at three DOE labs, NIH, HHS agency, security-device manufacturer |
| March 2026 | Vulnerability scanning of U.S. Senate and a U.S. hospital | Unsuccessful |
| June 2026 | QScan scanning of a U.S. election system | Observed |
The advisory also notes successful data thefts from unnamed defense contractors, financial institutions and universities in May 2024, matching the affidavit’s language on confirmed victims outside the pure federal-agency list.
Read as a single arc, the sample shows persistent reconnaissance punctuated by bursts of successful theft. Early years lean on scanning and one blocked VPN attempt. The 2024 window holds the heaviest confirmed damage. The 2026 entries return to scanning against the Senate, a hospital, and an election system, with the Senate and hospital probes marked unsuccessful.
That pattern helps explain why the Friday wording fix could shrink the victim roster without shrinking the threat picture. Failed probes still demonstrate intent and access-seeking. Successful 2024 thefts still demonstrate result.
The September 2024 Labs and Health Agency Hits
Those September 2024 intrusions remain the clearest confirmed government-side compromises. Three Department of Energy national laboratories, the National Institutes of Health, an HHS agency and a U.S. security-device manufacturer were breached with zero-day exploits against Ivanti Cloud Services Appliance software. The affidavit treats them explicitly as victims.
Lumen Technologies’ Black Lotus Labs, which tracked the infrastructure for a year, published a Black Lotus Labs description of the quartermaster model. Researchers described four operational pieces: the QScan reconnaissance tool, an encrypted relay network called Fast Labyrinth, physical QTRouter devices, and a QTProxy management layer. The setup let operators profile and steal data from military, government, university, aerospace, healthcare, financial and energy targets while hiding origin.
- QScan: reconnaissance and automated infection of IoT devices
- Fast Labyrinth: encrypted relay network for traffic movement
- QTRouter: physical devices forming the obfuscation fabric
- QTProxy: management layer over the proxy pool
On X, technical accounts circulated ELF binaries tied to the proxy platform and noted directory listings from related servers that had briefly exposed Vshell command-and-control. Crowd reaction focused less on the later wording edit and more on the sheer reach of the IoT infection layer and the reuse of commercial proxies.
The zero-day Ivanti path explains why the lab and health hits land differently from the NASA footnote. Patching closed the earlier Pulse Secure route before compromise. The September 2024 wave used a vulnerability that was still unannounced, and the affidavit records completed intrusions.
Beijing’s Response and the Pattern of Prior Disruptions
The Chinese Embassy in Washington did not immediately answer questions about the Friday correction. In its initial reaction to the Wednesday seizure announcement, a spokesperson said the United States uses cybersecurity to “smear or discredit China” and that China “opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies.”
The QTFY action sits in a sequence of FBI technical operations against PRC-linked botnets. In 2023 the government disrupted a botnet used by Volt Typhoon to conceal critical-infrastructure hacking; that earlier earlier Volt Typhoon botnet disruption also relied on court-authorized steps against infected U.S. routers. Similar takedowns hit Flax Typhoon infrastructure in 2024 and PlugX malware in 2025.
- 2023: Volt Typhoon botnet disrupted to stop concealment of critical-infrastructure hacking
- 2024: Flax Typhoon infrastructure taken down
- 2025: PlugX malware operation hit
- August 26 action: QScan and QTRouter domains seized against QTFY
Each episode pairs a technical cut with a public attribution to PRC-linked actors. Router-level and botnet-level pressure recurs because those layers hide origin and blend malicious traffic into ordinary paths. The QTFY seizures extend that playbook to a quartermaster-style enablement service rather than a single actor’s exclusive toolkit.
State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.
Attorney General Todd Blanche, Justice Department press release
How the Enablement Model Separates Tools From Customers
The government’s account of Nanjing Xinjiuwei Network Technology Company describes a vendor-style relationship rather than a single closed hacking team. Clients allegedly include the Ministry of State Security and the People’s Liberation Army. The platforms themselves mix infected IoT devices, commercial proxies, and leased virtual private servers.
That mix is the practical core of the quartermaster framing from Black Lotus Labs. Reconnaissance tooling finds and infects devices. Relay and router layers move traffic. A proxy management layer keeps the pool usable. State customers can then draw on the resulting cover without owning every infected camera or router themselves.
Domain hard-coding tied the whole stack to the seized infrastructure. Court authorization against those domains therefore struck both the criminal service layer and the state-use pathway that depended on it. The affidavit’s victim list still rests on separate intrusion findings, not on the mere existence of the platforms.
Public attention on X to ELF binaries and brief Vshell directory exposure fits the same picture. Researchers and operators alike could see fragments of the proxy stack when servers were misconfigured. Those glimpses reinforced the scale claim without replacing the affidavit’s case-by-case compromise findings.
Why the Correction Still Leaves Agencies Under Pressure
The Friday edit changes labels, not the underlying targeting history. NASA’s blocked 2019 exploit, the unsuccessful 2026 Senate and hospital scans, and the observed election-system scanning all remain part of the advisory timeline. They show continued pressure even where compromise is not alleged.
For the entities named as victims, the record is sharper. Three DOE national laboratories, NIH, an HHS agency, and a U.S. security-device manufacturer appear with September 2024 zero-day intrusions attached. May 2024 data theft from more than 300 organizations, including defense contractors, financial institutions, and universities, widens the non-federal damage line.
| Category | Examples drawn from filings | Public status |
|---|---|---|
| Confirmed victims | Three DOE labs, NIH, HHS agency, security-device maker | Affidavit calls them victims |
| Targeted, not shown compromised | NASA (patched), Senate and hospital scans | Attempts failed or unsuccessful |
| Broad theft set | Defense contractors, financial institutions, universities | Data exfiltrated, May 2024 |
The correction therefore disciplines the federal-agency roster while leaving the defense-industrial and financial theft claims untouched. Secondary coverage that flattened every listed name into a breach story now sits at odds with the affidavit’s narrower victim set.
Why the Target-Versus-Victim Line Still Leaves a Hard Record
Messages seeking further clarification from the FBI and the Cybersecurity and Infrastructure Security Agency were not returned on Friday. Reuters and other outlets noted that the public still lacks a complete public map of exactly which named agencies suffered confirmed compromise beyond the DOE labs, NIH and HHS entity named in the affidavit.
The edit protects accuracy. It also arrives after initial headlines had already framed the Senate, Fed and NASA as breached. Public memory and secondary reporting often retain the first version. At the same time, the surviving record is still severe: multi-year targeting of the most sensitive civilian and research networks, successful zero-day intrusions inside national laboratories, and large-scale data theft from the defense industrial base and financial sector.
Agencies that remain only on the target list still face the operational cost of repeated probing. Scanning against election systems and hospitals in 2026, even when marked unsuccessful or merely observed, keeps those networks inside the campaign’s scope. The difference between target and victim is real for attribution. It is thinner for defenders who must assume continued interest.
The platforms are offline. The affidavit and advisory remain the detailed public baseline. Further unsealing or victim notifications could still expand or refine the compromised list, but the core claim of a persistent China-linked enablement model that mixes commercial IoT botnets with state customers is unchanged by the Friday wording fix.
-
TECH1 year agoWhere Garmin Watches are Made and How They are Assembled
-
AUTO3 months agoTesla’s Roadster Is ‘a Few Weeks Away,’ Says Its Chief Designer
-
NEWS10 years agoSamsung Releases Galaxy Note7 TV Ad as Reddit AMA Leaks Specs
-
NEWS10 years agoAndroid 7.0 Nougat Rolls Out To Nexus Devices With New Emoji, Features
-
FINANCE9 years agoCardano Price Surges as ADA Enters the Crypto Top Ten List
-
NEWS10 years agoPre-Order the First Camera Made for Facebook Live Streaming Video
-
FINANCE1 year agoBinance Suspends Trading and Withdrawals for a System Upgrade
-
FINANCE9 years agoRChain Price Jumps Nearly 150% to a New All-Time High of $2.03
