FBI smashes "Chinese state-linked botnet platform" targeting US critical infrastructure

"We’re looking at a persistent, organized, and sustained effort to get inside the institutions that keep the country running."

Share
Critical infrastructure is under threat amid growing geopolitical tensions (Image: Unsplash)
Critical infrastructure is under threat amid growing geopolitical tensions (Image: Unsplash)

The FBI and Justice Department have seized two hacking platforms that a Chinese "state-sponsored" group called QTFY allegedly used to attack American critical infrastructure targets.

Court documents claim that QTFY offers "computer hacking services" to customers including the PRC’s Ministry of State Security and the People’s Liberation Army. Its victims included NASA, the Federal Reserve, and US energy laboratories.

The group's services include two platforms, QScan and QTRouter. The first searches for internet-of-things (IoT) devices worldwide, infects them and adds them to a botnet called QTRouter made up of QTFY-controlled devices.

“In addition to compromised IoT devices, QTRouter uses commercial proxy services and leased virtual private servers, serving as an "obfuscation network" that masks the true identity of the threat actors.”

QTFY used compromised computers outside China, sometimes located near its targets, to disguise the origin of its attacks. The seized domains were hard-coded into the QScan and QTRouter malware and were essential for communication and authentication, meaning the court-authorized seizures effectively disabled both platforms.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks."

The operation is the latest in a series of FBI disruptions targeting Chinese state-sponsored hacking groups, following operations against Mustang Panda’s PlugX malware in 2025, Flax Typhoon’s botnet in 2024 and Volt Typhoon’s critical infrastructure botnet in 2023.

Military-industrial complexity

The FBI's investigation drew on independent research from security professionals at Black Lotus Labs, which said a key infrastructure provider was operating as a "quartermaster" whose operations "demonstrate the high degree of industrialization occurring within China-nexus cyber operations.

"Its operations integrate reconnaissance, proxy orchestration and operational routing into a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure," researchers wrote.

"Rather than conducting direct intrusions, quartermaster operations facilitate complex obfuscation networks and distributed scanning frameworks, offering pre-packaged stealth, target verification telemetry and non-attributable transit layers to multiple consumers simultaneously.

"From a threat-hunting perspective, these shared networks represent a critical operational chokepoint: taking down a single quartermaster’s obfuscation network systematically degrades the capabilities of multiple active threat campaigns at once."

"Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat."

The wider threat to critical infrastructure

The FBI's disruption of adversary infrastructure comes amid growing threats to the critical systems underpinning society.

Peter Bentley, Chief Operating Officer of Patero, told Machine: "America’s critical infrastructure isn’t just a hypothetical target—it’s being hit right now.

"We’re looking at a campaign that is persistent, highly organized, and deeply strategic - a sustained effort to get inside the institutions that keep the country running. These state-sponsored actors are playing the long game, and their real goal is often just staying inside the network without being noticed.

"The problem is that our infrastructure isn't one big, tidy network. It’s a sprawling, messy "system of systems" that connects everything from our water and power to our banks and hospitals.

"A lot of this was built decades ago. Now, we’re plugging that old legacy equipment into modern apps, the cloud, and mobile devices. Every new connection makes life easier, but it also hands hackers another door to try and kick down."

A recent ransomware attack on a US water-sector technology supplier also underlined the growing risk to infrastructure.

READ MORE: UK builds experimental AI surveillance system using buried fibre-optic cables

Hackers stole hundreds of gigabytes of data from a company whose control systems are used by wastewater facilities, with the allegedly stolen files referencing local government customers and a U.S. military facility.

Around 200 of its SCADA systems are accessible from the internet, although there is no evidence that operational water systems were compromised.

Commenting on the story, Jake Taylor, Head of Public Sector EMEA at Filigran said: "Attacks against critical infrastructure are increasing, but the bigger concern is the frequency, sophistication and intent behind them.

"This, and recent reports of Iran-linked actors disrupting a UK energy facility in the past week highlight how infrastructure across NATO is increasingly being tested for vulnerabilities and resilience. 

"For cyber threat intelligence teams, the focus must move beyond individual incidents to identifying threat actor behaviour, patterns and intent - understanding who is targeting infrastructure, why, what they may target next, and the early indicators that could provide warning before disruption occurs.

"The goal is simple: move from reacting to attacks to anticipating them."

Follow Machine on LinkedIn