Chinese state-sponsored hackers broke into computers at NASA, the Federal Reserve, the US Senate, and the Department of Justice itself.
The Justice Department and FBI unsealed court documents this week naming the group QTFY, a hacking-for-hire outfit allegedly built for a company called Nanjing Xinjiuwei Network Technology. QTFY ran two tools, QScan and QTRouter, that scan for and hijack internet-connected devices, folding them into a botnet used as a proxy network to hide the hackers' traffic. Using that infrastructure, the group breached computers at NASA, the Federal Reserve, the Senate, the DOJ itself, the Department of Energy, Health and Human Services, and the National Institutes of Health. FBI San Diego and the FBI Cyber Division seized the domains behind QScan and QTRouter to shut the platform down.
A hacking-for-hire model means Beijing-linked operators don't need to build every tool themselves - they can rent access, the same way ransomware gangs sell affiliate kits to less sophisticated criminals. That an IoT botnet was flexible enough to reach a space agency, a central bank, and a legislature suggests the access-for-sale approach scales well beyond any single victim. It's also worth noting the DOJ counts itself among the breached, which undercuts any read of this as a clean law-enforcement win rather than a still-unfolding exposure.
This is the same playbook the FBI used against PlugX and earlier Chinese IoT botnets - seize the infrastructure, publicize the takedown, and wait for the next rental service to take its place.