Credit: REUTERS

US Revises China Hack Claims: What the Correction Reveals About the QTFY Campaign

There has been a quiet change in the US public story of the major Chinese cyber espionage operation in which, at first, the story went that a number of top government agencies had been “hacked”, while now the story is that these were “targeted” agencies with only some being successful in breaching their defenses. The change does not make any difference to the main accusation, that a Chinese group has been operating a sustained intrusion operation against the US government and critical infrastructure for years on end, but it draws a finer distinction between attempts and successes.

From “victims” to “targets”: the DOJ’s correction

The correction centers on wording in the Department of Justice’s August 26 announcement, which initially described agencies including the US Senate, Federal Reserve, NASA, and the Department of Justice as “victims” of computer intrusions by a Chinese state‑sponsored group. Two days later, DOJ issued a revised statement acknowledging that the original release

“described all agencies as victims whereas the government’s affidavit made clear that all were targeted but only some were compromised,”

according to the department’s own clarification.

In the corrected language, those same bodies are referred to as “among the targets of QTFY,” the name US authorities use for the hacking group, rather than as uniformly breached entities. The change aligns the public messaging more closely with the underlying FBI affidavit, which had always used “targeted” to describe the full set of named agencies while identifying a smaller subset as confirmed victims.

The QTFY operation: scope, tools, and alleged patrons

The main focus in the case at hand is a cyber gang known as QTFY, which has been active since at least 2018, according to statements by U.S. officials who refer to the hackers as QT and QTCYBER. According to documents made available by court orders in the Southern District of California, QTFY is described as a People’s Republic of China state-sponsored hacking group that has been hired by the China-based firm called Nanjing Xinjiuwei Network Technology Company. This company was responsible for creating and operating the two major hacking platforms referred to as QScan and QTRouter. 

According to statements from the FBI and Department of Justice, QTFY has been providing services of computer hacking to its clients, including the People’s Republic of China’s Ministry of State Security and the People’s Liberation Army. The QScan is said to be the vulnerability scanning and exploitation platform that helps detect and exploit the vulnerabilities of internet-facing systems. The QTRouter is the obfuscation network that has been routing the malicious traffic via compromised devices.

Who was in the crosshairs: agencies, labs, and critical infrastructure

The FBI affidavit states that since 2018, QTFY “targeted” US federal networks including those of NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. Beyond those headline names, the campaign is alleged to have struck three Department of Energy national laboratories, at least one HHS agency, and a wide array of non‑government entities, including hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.

The amended statement from the DOJ highlights that the Senate, Federal Reserve, NASA, and DOJ were “among the targets of QTFY,” not indicating that each one had been confirmed as a breach victim, while the affidavit names multiple organizations—including the NIH, some DOE facilities, and certain HHS agencies—that have been compromised. The end result, in reality, is a campaign that reached out widely in its scope but achieved a more limited number of breaches within that effort.

The takedown: domain seizures and disruption of infrastructure

On August 26, the Justice Department and FBI announced they had seized three internet domains tied to QTFY’s infrastructure, rendering key parts of the botnet’s command‑and‑control system inoperable because those domains were hardcoded into the malware. The seized domains supported the QScan and QTRouter platforms, which prosecutors say were critical to the group’s ability to conduct reconnaissance, exploit vulnerabilities, and blend malicious traffic with legitimate user activity.

In a joint statement, the agencies said the action

“disrupted a China state‑sponsored hacking operation responsible for break‑ins at numerous sensitive U.S. federal agencies and critical infrastructure,”

while also warning that the group had targeted networks

“operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.”

The National Security Agency subsequently issued its own advisory detailing QTFY’s toolset, including QScan’s use against known vulnerabilities and QTRouter’s role in obfuscating command‑and‑control traffic.

Why the wording matters: accuracy, escalation, and diplomacy

“Targeted,” as opposed to “hacked,” for some agencies, is not just a change of wording. Within the framework of the cyber incidents report, the “targeted” definition can include both compromised and unsuccessful intrusions where the latter ones were either stopped or never confirmed, while “hacked” or “victim” usually indicates a confirmed breach. By adopting the wording used in the affidavit, the US Department of Justice minimizes the chances of exaggeration in the very sensitive geopolitical setting, but still keeps the essence of the prolonged campaign backed by the Chinese government intact. 

The timing is also worth noting. In the context of the Chinese officials’ objections to the claims about state-sponsored hacking by the United States, and in light of mutual cyber espionage accusations made by the two countries, it becomes important to use precise terminology so as not to worsen the situation diplomatically, but to keep credibility with cybersecurity experts and the Congress.

What remains unchanged: the core allegations

Despite the change in wording, a number of central statements remain intact. First, the U.S. administration still contends that QTFY is a China-sponsored, state-affiliated group conducting cyber espionage against U.S. targets for almost a decade now. Second, it still contends that QTFY’s operations have penetrated deeply into the U.S. government, with proven intrusions into a number of government institutions of the highest level of security – NIH and DOE national laboratories, as well as attempted intrusions into other key agencies. Third, the government’s characterization of the group’s business model is left intact: it is a combination of hackers-for-hire service as well as direct assistance to Chinese intelligence/military customers, all of which is possible thanks to massive proxy and botnet infrastructure. Domain seizures are represented not as a solution but as an attack on a resilient ecosystem that constantly upgrades itself.

Implications for US agencies and critical infrastructure

For federal government networks, the event reiterates the continued threat posed by intrusions that may go undetected for an extended period of time, especially when dealing with extensive environments like laboratories and health organizations. The mention of successful infiltration on NIH, HHS, and DOE labs by the affidavit underlines the importance of the data that may be breached, from biomedical data to energy-related information that has security ramifications. For corporations, the list of targets, which include hospitals, telecommunications networks, power utilities, banks, and military contractors, reiterates a well-known but unpleasant truth – critical infrastructures continue being primary prey for state-sponsored hackers looking for strategic intelligence. QTRouter, in particular, shows the dangers of using infected internet-connected devices to hide attacks on key targets.

Share this page:

Related content

Russia claims it has captured three villages in Ukraine’s Donetsk and Sumy regions

Russia claims it has captured three villages in Ukraine’s Donetsk and Sumy regions

The declaration made by Russia’s Defense Ministry on 29 August 2026 announcing that their troops have taken control of three more towns in Ukraine follows a familiar trend seen during…
US Military Laser Strike on Cartel Drones Marks New Border Era

US Military Laser Strike on Cartel Drones Marks New Border Era

The U.S. military’s use of a high-energy laser to destroy three Mexican cartel drones near the southern border is more than a tactical counter-drone success; it is a signal that…
US, South Korea, Japan to Hold North Korea-focused Nuclear Missile Drill

US, South Korea, Japan to Hold North Korea-focused Nuclear Missile Drill

The United States, South Korea, and Japan are set to conduct a high-profile, North Korea–focused nuclear missile–defense exercise in early September, underscoring a deepening trilateral security architecture even as Pyongyang…