[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fX1Tyy-AmurbuyqfgY1P082FrwzwHluwkKPiEwVHgZsE":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"96432961-4dbf-46ae-8f3f-b36e7a297dd0","DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims","doj-corrects-china-hacking-claim-says-u-s-agencies-were-targets-not-victims-0a5826","The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department","The U.S. Department of Justice (DoJ) has revised a previous statement, clarifying that several U.S. agencies were targets, not victims, of Chinese threat actors. The state-sponsored group QTFY, affiliated with China, was identified as the actor behind the cyber espionage activities, which have been ongoing since 2018. The DoJ's update emphasizes that while many organizations were targeted, not all were necessarily compromised.","DoJ corrects China hacking claim, stating US agencies were targeted, not victims.","DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims Ravie LakshmananAug 31, 2026Cyber Espionage \u002F IoT Botnet The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were some of the victims of \"computer intrusion activity\" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China (PRC). In the newly updated statement, the aforementioned agencies have been listed as \"among the targets of QTFY.\" The update was reported by Reuters over the weekend. \"Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures,\" the DoJ said in a note. According to the affidavit, QTFY (aka QT AND QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, adding payments from the Ministry of State Security (MSS) suggest that the company conducts malicious cyber activities on behalf of Beijing. The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors. Described as a technical quartermaster, QTFY has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. Two of the core products in its arsenal are QScan, a vulnerability scanning and exploitation platform, and QTRouter, which is an obfuscation network. In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN. The change in wording is significant as it suggests that while the activity may have targeted a broad range of organizations, only some of them were actually compromised. The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com), effectively neutralizing the malware's functions. Lumen Black Lotus Labs has revealed that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, creating a decentralized botnet of infected IoT devices and leased VPSs that enables them to obscure the true origins of the malicious activity. QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter. The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws. The entire architecture underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity. \"By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets,\" the affidavit alleged. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  botnet, cyber espionage, Government security, iot security, Nation-State ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fdoj-corrects-china-hacking-claim-says.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjHmPwSKHINCGncOKbSs9X05lJ2CJQivbfLYQ6LP3njVHAc-4fgSYJz-C1u6SUiFEtcF4ddjW3PBayFsVaF2a03OOkaLfWlg8pxJelp5bEhJT0LEv8-XPs9bUf8ruFcGOzjWAbumEJ4Veirq9lAAalOThmUfD0i19Mo5X_HpDcI21_5pJp7WsA8OPh74Ad_\u002Fs1600\u002Fjustice.jpg","2026-08-31T07:56:53+00:00","2026-08-31T10:00:13.514835+00:00",8,[18,21,23,26,29,31],{"name":19,"type":20},"QTFY","threat_actor",{"name":22,"type":20},"QT AND QTCYBER",{"name":24,"type":25},"Nanjing Xinjiuwei Network Technology Co","vendor",{"name":27,"type":28},"QScan","product",{"name":30,"type":28},"QTRouter",{"name":32,"type":33},"Fast Labyrinth","campaign","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":34,"icon":36,"name":37,"slug":38},null,"Nation-state","nation-state",[40,42,47],{"category":41},{"id":34,"icon":36,"name":37,"slug":38},{"category":43},{"id":44,"icon":36,"name":45,"slug":46},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53,57,61,63,65],{"type":54,"value":55,"context":56},"cve","CVE-2019-11510","Vulnerability exploited by QTFY to target NASA",{"type":58,"value":59,"context":60},"domain","qtproxy[.]xyz","Disrupted domain linked to QScan and QTRouter",{"type":58,"value":62,"context":60},"qt-proxy[.]org",{"type":58,"value":64,"context":60},"qt-team[.]com",{"type":58,"value":66,"context":67},"fastlink[.]ws","Chinese commercial proxy service used in the relay network"]