WASHINGTON (TNND) — Federal authorities say they have shut down key online systems linked to two hacking platforms allegedly used by a China state-sponsored group to target U.S. critical infrastructure and other sensitive networks.

The Justice Department and FBI announced Aug. 26 that they seized internet domains connected to QScan and QTRouter. DOJ said the platforms were allegedly used by a group identified in court documents as QTFY, which was employed by the China-based Nanjing Xinjiuwei Network Technology Company.

DOJ identified the alleged targets as NASA, the Federal Reserve, the departments of Justice, Energy and Health and Human Services, the National Institutes of Health and the U.S. Senate.

According to DOJ, QTFY sold hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army.

DOJ said QScan searched for and infected thousands of internet-connected devices worldwide. Those compromised devices were then added to the QTRouter network. DOJ described QTRouter as a system designed to hide the source of malicious activity, making it appear to come from outside China, sometimes from devices located near the targeted networks.

The seized domains were built into the malware and used for communication and authentication. DOJ said the court-authorized seizure made both QScan and QTRouter inoperable.

An affidavit said the infrastructure had been used to compromise U.S. and global critical infrastructure and sensitive networks since at least 2018. Other alleged targets included hospitals, telecommunications providers, power companies, financial institutions and defense contractors, as well as four unnamed companies in the U.S. and South Korea.

Officials did not say how long the intrusions lasted or whether they caused damage.

DOJ said the action follows earlier FBI efforts to disrupt China-linked malware and botnets, including PlugX in 2025, Flax Typhoon in 2024 and Volt Typhoon in 2023.