Chinese hackers target NASA and key US agencies, DOJ alleges

Some cyberattacks start with a suspicious email. Others begin somewhere you would probably never think to look. It could be an old router in someone’s home. Maybe it is a forgotten security camera that still connects to the internet. Hackers can compromise vulnerable connected devices and use them to disguise where an attack really comes from.

That tactic played a role in a China-linked hacking operation that U.S. authorities say took aim at some of America’s most sensitive networks.

On Aug. 26, the Justice Department and FBI confirmed intrusion attempts since 2018 against NASA, the Federal Reserve, the Justice Department and the U.S. Senate. Other targets included the Department of Energy, Department of Health and Human Services and National Institutes of Health. 

FBI WRAPS UP CYBERCRIME OPERATION TARGETING GLOBAL NETWORKS PREYING ON AMERICANS

Four unnamed companies in the United States and South Korea were reportedly targeted as well. The names behind the operation sound like something from an IT department: QScan and QTRouter. Yet what these tools allegedly did should get your attention.

Here is how the hacking operation worked, how authorities shut it down and what you can do to keep your own connected devices from becoming part of an attacker’s network.

THIS SATURDAY! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats

Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt “CyberGuy” Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. 

No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

According to the Justice Department, a Chinese state-sponsored group known as QTFY created and operated QScan and QTRouter. Federal officials say the group worked for the China-based Nanjing Xinjiuwei Network Technology Company. The Justice Department alleges that the company offered hacking services to paying customers, including China’s Ministry of State Security and People’s Liberation Army.

Authorities say QTFY infrastructure has been used to compromise critical infrastructure and other sensitive networks since at least 2018. Court documents also describe targets that included hospitals, telecommunications providers, financial institutions and defense contractors.

CyberGuy reached out to NASA about the Justice Department’s announcement.

“NASA is committed to the cybersecurity and the protection of our systems,” NASA spokesperson Jennifer Dooren said. “We work closely with our federal partners, including the Cybersecurity and Infrastructure Security Agency, to quickly address identified vulnerabilities. We continuously collaborate with software partners and actively monitor and assess our networks, software and data for potential risks. 

“For security reasons, NASA does not comment on specific reports of potential vulnerabilities or incidents. For additional information regarding this matter, please contact the Department of Justice.”

We also reached out to the Chinese Embassy in Washington about the Justice Department’s allegations.

“I am not aware of the specifics you mentioned,” an embassy spokesperson told CyberGuy. “China is a firm defender of cybersecurity. The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law. We urge the U.S. side to stop using cybersecurity issues to smear or discredit China. 

“China firmly opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies.”

After we sent the embassy the specific Justice Department release outlining the allegations involving QScan and QTRouter, the embassy told CyberGuy it had “no further information to add at the moment.”

China has repeatedly denied accusations that it sponsors malicious cyber activity. What stands out here is the infrastructure behind the attacks. Federal investigators describe a system designed to find vulnerable devices and then use some of those devices to help hide malicious activity.

QScan handled the hunting. The Justice Department says the platform scanned for vulnerable systems and automatically infected thousands of internet-of-things devices around the world. Those compromised devices could then become part of QTRouter.

QTRouter served as what investigators call an obfuscation network. In everyday language, it helped conceal where an attack really came from. The network included compromised IoT devices along with commercial proxy devices and leased virtual private servers.

Attackers could route malicious communications through that infrastructure. As a result, the activity could appear to originate outside China or even near the network being targeted. That creates a serious challenge for security teams trying to track an attacker.

Think about all the internet-connected equipment people rarely touch after setting it up. A router might sit in the corner for years. A security camera could keep running long after its manufacturer stops releasing updates. Hackers pay attention to forgotten devices because those devices can give them somewhere to hide.

FBI Director Kash Patel emphasized how the infrastructure helped conceal the attackers. 

“These tools were used by PRC cyber actors to hide the origin of their attacks,” Patel said.

TRUMP PLAN TAPS US FIRMS TO FIGHT FOREIGN CYBERCRIME

You were probably nowhere near the hackers’ list of targets. NASA and the Federal Reserve operate in a very different security world from your living room. However, the infrastructure behind these attacks creates a connection to everyday technology.

QScan allegedly infected IoT devices and pulled them into a larger network. Those compromised devices then helped disguise malicious traffic. So, an insecure connected device can become useful to an attacker even when the attacker has little interest in its owner.

You may never see a ransom note. Your smart device could continue working normally. Yet vulnerable equipment can potentially provide infrastructure for malicious activity happening somewhere else. That is one reason I keep telling you to pay attention to the router sitting behind the couch.

The Justice Department obtained court authorization to seize domains used by QScan and QTRouter. Those domains turned out to be a critical weakness. Federal officials say the domains were hard-coded into the malware and used for essential functions, including communication and authentication. Once authorities seized them, the Justice Department says QScan and QTRouter became inoperable. Investigators went after infrastructure that the hacking platforms needed to work.

Black Lotus Labs says targeting shared infrastructure like this can damage more than one cyber operation at a time. Its researchers wrote that “taking down a single quartermaster’s obfuscation network systematically degrades the capabilities of multiple active threat campaigns at once.”

Black Lotus Labs also says it shared threat intelligence with U.S. government agencies about emerging risks and null-routed traffic to known infrastructure used by the operators. The researchers describe the operation as a kind of cyber “quartermaster,” providing shared reconnaissance, routing and concealment infrastructure that multiple China-linked threat actors could use. That approach has become a recurring part of the U.S. response to China-linked cyber operations.

The latest operation follows several previous federal efforts targeting Chinese hacking groups. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the China-sponsored Mustang Panda group. In 2024, federal agents disabled a botnet made up of hundreds of thousands of infected IoT devices associated with Flax Typhoon.

The FBI previously disrupted another botnet used by Volt Typhoon to conceal attacks targeting U.S. and foreign critical infrastructure. CyberGuy has also reported on Salt Typhoon, the China-linked hacking campaign that penetrated major American telecommunications networks. These operations work differently. However, they show how valuable compromised infrastructure can become for state-backed hackers.

You cannot personally stop a nation-state hacking operation. However, you can make your own devices much harder for attackers to compromise or use as part of their infrastructure.

Your router runs software called firmware, and security fixes are often delivered through firmware updates. Open your router’s app or administration page and check for updates. If your router supports automatic updates, turn them on.

An old router can keep working long after the manufacturer stops protecting it. Check your router’s model number on the manufacturer’s website to see whether it still receives firmware and security updates. If it has reached the end of its life, replace it with a supported model. The FBI has previously warned that cybercriminals actively exploit aging routers that no longer receive security patches.

Do not leave the router’s administrator account using its original or default password. Create a long, strong and unique password that you have never used for another account. A password manager can help you generate and securely store it. If your router offers two-factor authentication (2FA) for administrator access, turn it on.

Your Wi-Fi network should also have its own strong, unique password. Avoid names, addresses, phone numbers or other information someone could easily guess. Do not reuse the password you use to administer the router.

Check your router’s wireless security settings. WPA3-Personal offers stronger protection and should be your first choice when your router and devices support it. If WPA3 causes compatibility problems with older devices, use WPA2-Personal with AES or a WPA2/WPA3 compatibility mode. Avoid older WEP and WPA security.

Most people have no reason to change their router settings while away from home. Look for a setting called Remote Management, Remote Administration or WAN Access. Disable it unless you specifically need it. The FBI has specifically warned that exposed remote administration can give attackers another way to target vulnerable routers.

Wi-Fi Protected Setup, or WPS, can make connecting devices easier. However, most people do not need to leave it enabled after setup. Also check Universal Plug and Play, or UPnP. It allows devices to automatically request network access and open connections through your router. If none of your devices require it, turning UPnP off can reduce unnecessary exposure.

Most routers include a built-in firewall. Check your router settings and make sure the firewall remains enabled. Avoid changing advanced firewall settings unless you understand what they control.

If your router supports a guest network or dedicated IoT network, consider putting security cameras, smart plugs, speakers and other connected gadgets there. Separating those devices from the laptops and phones where you keep sensitive information can limit an attacker’s reach if one smart device gets compromised.

Your router is only one piece of the network. Check security cameras, doorbells, smart TVs and other connected devices for software or firmware updates. Enable automatic updates when available. If a smart device has reached the end of its support life and no longer receives security fixes, consider replacing it.

Some cameras, smart home hubs and other IoT gear come with preset administrator credentials. Change those passwords during setup. Use a unique password for each important device or account.

Open your router’s app or administration page and look at its list of connected devices. Make sure you recognize what is there. If you see a device you cannot identify, investigate it. Change your Wi-Fi password if necessary and reconnect only the devices you trust.

An old security camera in the garage or smart plug sitting in a drawer can still be connected to your network. Remove devices you no longer use from your Wi-Fi. Disconnect or reset the hardware before getting rid of it.

Install operating system and security updates on your computers, phones and tablets as soon as practical. Strong antivirus software can also help detect malware, malicious downloads and dangerous links before they create another route into your devices. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

Unexpected settings changes, unfamiliar devices appearing on your network, repeated connectivity problems or unusual router behavior deserve attention. If something looks wrong, reboot the router and check its settings for changes you did not make. If suspicious activity continues, contact your internet provider or router manufacturer. You may need to factory-reset the router and set it up again using trusted settings.

What catches my attention here is how much effort went into hiding the origin of these attacks. The hackers allegedly built infrastructure that could scan for vulnerable devices, compromise them and then use those devices as cover. Federal agents eventually found a pressure point by seizing domains the malware needed to operate. That is a significant win. Still, one disruption leaves a much larger cyber fight in place. 

State-backed groups keep looking for vulnerable infrastructure because forgotten connected devices are everywhere. Your router may seem like nothing more than a box keeping Netflix running and your phone online. To an attacker, an unpatched device can have an entirely different purpose. For you, the lesson is surprisingly practical. 

That router you have ignored for five years deserves a checkup. The same goes for old smart home gear that still connects to the internet. If a manufacturer stopped protecting a device, think carefully about whether you want to keep giving it access to your network.

Do you think the U.S. is doing enough to stop China-backed hackers from targeting American networks and using vulnerable devices to cover their tracks? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Post