FBI Disrupts Chinese Proxy Network Used to Hack US Agencies
A government contractor allegedly supplied relay infrastructure to China's military and intelligence services for years-long espionage campaigns.

The FBI has dismantled a proxy network that Chinese state-sponsored hackers used to penetrate dozens of US government agencies and critical infrastructure targets over a span of at least six years, according to a Department of Justice announcement Wednesday.
The operation targeted two tools—QTRouter and QScan—operated by a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company. Federal prosecutors allege the company functioned as a "quartermaster" for China's hacking operations, providing customers including the Ministry of State Security and the People's Liberation Army with access to networks of compromised devices that masked the origin of their attacks.
The scope of intrusions
According to court documents, hackers using the proxy infrastructure breached an extensive list of US government entities: NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and even the Justice Department itself.
Beyond government agencies, the FBI affidavit identifies targeted sectors including power companies, telecommunications providers, hospitals, financial institutions, and defense contractors. The documents do not specify which organizations were successfully compromised or the extent of any breaches.
How the infrastructure worked
QScan was designed to identify vulnerabilities in internet-of-things devices that could be hijacked and added to botnets serving as proxy relay points. QTRouter then managed customer access to these compromised device networks, along with rented commercial virtual private servers.
More recently, the operation shifted tactics by hijacking VPN services typically used by Chinese citizens to circumvent the Great Firewall censorship system. This approach buried malicious state-sponsored traffic within legitimate user activity, making detection significantly harder.
"It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were coopting," said Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, which collaborated with federal authorities on the disruption.
Why it matters
This takedown exposes the privatized infrastructure supporting China's global hacking apparatus. Rather than building all capabilities in-house, Chinese intelligence and military services increasingly rely on contractors to provide the technical scaffolding for espionage campaigns. The years-long timeline and breadth of targets demonstrate both the scale of China's intelligence collection priorities and the challenge of defending against adversaries who can constantly adapt their methods. While this disruption creates operational setbacks, security researchers expect the hackers to rebuild with new infrastructure.
What happens next
The FBI seized key domains hardcoded into the proxy tools, while Lumen null-routed certain domains to render them inoperable. However, no individual charges were announced alongside the infrastructure takedown.
Rouse characterized the hacking campaigns as broad espionage focused on information collection rather than the infrastructure disruption objectives associated with China's separate Volt Typhoon operation. He expects the Nanjing company and its clients to adapt and establish new relay networks.
"I think this will have a direct effect on the company and its perception in China. This is an egg-on-the-face moment for them," Rouse said. "I think we can also safely assume they'll pivot and stand up new infrastructure."
These details were first reported by WIRED.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call

