A court order issued by the U.S. Department of Justice on August 26 dismantled a chain of Chinese national cyber operations hidden in cyberspace into several entities that could be reviewed by the court: a Nanjing company, two attack platforms, a group of U.S. government agencies, and the Chinese Ministry of National Security and the Chinese People's Liberation Army directly directed by the U.S. government.

According to court documents released by the U.S. Department of Justice, the Federal Bureau of Investigation and the Department of Justice have seized the domain names used by QScan and QTRouter. The U.S. side said the two platforms were created and operated by Nanjing Xinhai Network Technology Co., Ltd. in China and used by a Chinese state-supported hacking organization known as QTFY. The U.S. government said the operation lost the two platforms because the seized domain names were hard-encoded into malware and undertook communication and authentication functions.

From NASA to the U.S. Federal Reserve: U.S. blocked Chinese hacking platforms, judicial documents pulled Nanjing companies into the same chain of responsibility with the Ministry of National Security and the Liberation Army

The victim list shows that this is not a common commercial cybercrime. The targets listed by the Department of Justice include NASA, the U.S. National Aerospace Agency, the U.S. Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Public Services, the U.S. National Institutes of Health and the U.S. Senate. Space, Finance, Energy, Justice, Biomedical and Legislative bodies are also targets, making the case a distinct national security attribute.

More importantly, the U.S. government’s description of the chain of responsibility. The Department of Justice said QTFY personnel were employed in Nanjing Xinjiang and related activities were linked to China’s national support system. The U.S. National Security Agency and the FBI issued a technical security notice on the same day, publishing technical indicators for related malicious cyber activities, and pushing the duration of traceable activity to at least 2018.

This puts Beijing’s long-standing cyberattack accountability issue into a new phase. Diplomatic statements can be denied, court seizures require investigators to submit materials to judges; technical attributions can be disputed, and domain names, servers, malware, employees, customers and funds can further form a chain of evidence.

原始来源 · justice.govJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical InfrastructureThe Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.justice.gov ↗

The U.S. Department of Justice also placed the operation in a consecutive record of China’s state-supporting cyber enforcement activities: destroying the Volt Typhoon-used bots network in 2023, fighting the Flax Typhoon infrastructure in 2024 and removing the PlugX monitoring malware associated with Mustang Panda from more than 4,000 U.S. computers in 2025.

The real question is: What are the business, tasks and personnel relationships between China’s national security agencies and the military with domestic cybersecurity enterprises? is the state project implemented through commercial companies? is the attack infrastructure provided by so-called private enterprises? is the government contracts, funding sources and customer lists of these enterprises not subject to independent review?

Xi continues to emphasize science and technology autonomy, cyber power and overall national security, while the U.S. judicial system is leaving a record from another direction: a group of Chinese commercial technology companies are referred to as the middle layer between national cyber operations and government agencies.

If this chain of “state agencies – contractors – hacking platforms – overseas targets” is eventually confirmed by more judicial evidence, then what China faces will be not just a cyber attack accusation, but a more serious question of international credibility: whether Beijing is using seemingly civilian commercial companies to provide deniable coats for national intelligence and military cyber operations.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.