US Seizes Chinese Hacking Tools Linked to Federal Reserve Breach

iconCryptoBriefing
Share
AI summary iconSummary
Federal Reserve news broke as the US Department of Justice and FBI seized two hacking platforms, QScan and QTRouter, tied to a Chinese state-backed group. The tools were used in a security breach targeting the Federal Reserve, NASA, and the Department of Justice. The operation, linked to Nanjing Xinjiuwei, allowed attackers to hide their tracks and infiltrate key sectors. The seizure happened on August 26 as part of a wider crackdown on PRC cyber activities.

The US Department of Justice and the FBI announced the seizure of two hacking platforms tied to a Chinese state-sponsored cyber group that allegedly breached some of the most sensitive institutions in the country, including the Federal Reserve.

The platforms, known as QScan and QTRouter, were attributed to a group called QTFY, which the US government linked to the Nanjing Xinjiuwei Network Technology Company. The tools reportedly allowed hackers to mask their origins while penetrating targets across the federal government and critical infrastructure sectors.

What was breached and how it worked

The list of named victims includes the Federal Reserve, NASA, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The affected targets also spanned critical infrastructure sectors including telecommunications providers, hospitals, and financial institutions.

Advertisement

QScan and QTRouter functioned as obfuscation tools, letting attackers route their intrusions through layers of misdirection so that tracing the source became exponentially harder.

The seizure of these platforms on August 26 represents part of a broader, ongoing US campaign against PRC-sponsored cyber operations.

The Federal Reserve angle

The Federal Reserve’s inclusion on the victim list is notable given prior documented targeting of the institution. A 2022 report from the Senate Homeland Security Committee revealed ongoing Chinese recruitment efforts targeting personnel at the Federal Reserve, known as the ‘P-Network.’ In January 2025, a senior adviser at the Federal Reserve was indicted on charges related to economic espionage, reaffirming the depth of collaboration between individuals and Chinese state actors.

Details remain sparse regarding the extent of the breaches, particularly in relation to sensitive policy data from the Federal Reserve.

The bigger picture on PRC cyber operations

What makes this case notable is the breadth of the target list and the specificity of the attribution. Naming the Nanjing Xinjiuwei Network Technology Company and the QTFY group signals that US intelligence has enough confidence in its evidence to go public.

The seizure of QScan and QTRouter disrupts the operational toolkit available to the group, at least temporarily. Cyber actors can rebuild, but losing established infrastructure forces them to start over, introducing delays and potential exposure during the reconstruction period.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.