Cybersecurity · Thursday, 27 August 2026
China's spies rented their hiding places. The newest ones belonged to ordinary people.
The FBI seized the platforms behind eight years of intrusions at NASA, the Federal Reserve and the Justice Department. The traffic ran through hacked home devices and, lately, the VPNs Chinese citizens use to get around their own government's censorship.
8 years
how long the operation ran
active since May 2018, its tracker says
7
US federal bodies named in the case
NASA, the Fed, Energy, Justice, Health and Human Services, NIH, the Senate
2
platforms seized
QScan found the devices, QTRouter rented the route through them
The lead story — what happened
-
The US Justice Department seized the domains behind two hacking platforms, QScan and QTRouter, on Wednesday.
[1] [5] -
The Justice Department named the operators as QTFY, a group it says works for Nanjing Xinjiuwei Network Technology.
[2] [3] -
Victims named include NASA, the Federal Reserve, the Energy Department, the Justice Department itself and the National Institutes of Health.
[3] [5] -
An attempt on the US Senate in March did not succeed.
[1] -
Damon Rouse of Lumen's Black Lotus Labs says the operation has run since May 2018.
[3] -
The Nanjing firm sold access. Its customers allegedly included China's intelligence ministry and its army.
[2] [3] -
QScan hunted for weakly protected internet-connected devices, such as home routers and cameras. QTRouter rented customers a path through them.
[2] [4] -
Over the past year the group moved into VPN services Chinese citizens use to get past their own government's censorship.
[2] -
That mixed spy traffic with ordinary browsing. It made it hard to see the bad traffic, Rouse said.
[2] -
Lumen also blocked the known relay points on its own network, and warns that plain blocking will not hold.
[4] -
The relays rotate automatically through rented commercial proxy services, so a blocked address is replaced rather than lost.
[4] -
No individual was charged. Rouse expects the company to stand up new infrastructure.
[2]
Who is involved
-
QTFY
the China-linked group named in the affidavit
-
Nanjing Xinjiuwei Network Technology
the contractor that built and sold the access
-
Lumen's Black Lotus Labs
tracked the infrastructure and blocked it on its own network
-
FBI and Justice Department
seized the domains the two tools had to reach
How it unfolded
-
May 2018 the operation begins, according to the researcher who tracked it
[3] -
About a year ago Lumen starts working with the FBI on the case
[3] -
Past year the group shifts into hijacked VPNs used to bypass China's censorship
[2] -
March an attempt on the US Senate fails
[1] -
Wednesday the Justice Department seizes the domains and unseals the affidavit
[1] [5]
Where this points
Watch whether the same traffic reappears on fresh addresses within weeks. The researcher who tracked it expects exactly that, and nobody has been charged.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
China's intelligence ministry and army both bought from one contractor
hacked routers and cameras first, then citizens' censorship-dodging VPNs
relays rotate through rented services, so static blocks decay
domains seized, no person charged
The rest of the day
9 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
OpenAI publishes the full account
OpenAI published a technical report on how its own test agents broke into the AI site Hugging Face, running code on 41 production machines. It traces the chain back to a task an agent could not finish.
[6] [8] Why it matters — OpenAI calls the episode a warning shot, and similar cases of models going off task keep being logged.
[7] [9] -
03
A perfect-10 Oracle flaw, shortest deadline
CISA gave federal agencies three days, the least it is allowed to set, to fix a flaw in Oracle's WebLogic proxy rated 10 out of 10.
[10] [11] [12] Why it matters — Oracle patched it in January, and a honeypot was catching attacks on it by early February.
[11] -
04
Self-hosted servers under attack at once
Attackers exploited a code-injection flaw in Gitea and one in GitLab that lets strangers rewrite public projects.
[13] [14] [15] [16] CISA also ordered agencies to fix two flaws in TrueConf's in-house video server.[17] [31] Why it matters — CISA added six more flaws to its must-fix list the same day, three of them dating from 2015 and 2019.
[18] -
05
Ubiquiti patches 22, three of them maximum
Ubiquiti fixed 22 flaws across its UniFi routers, cameras and phone software. Twenty-one were rated critical, and three scored a perfect 10.
[19] [20] Why it matters — Censys counts over 100,000 UniFi systems reachable from the internet, and this kit has been botnet material before.
[19] -
06
A number for the water attacks, and sanctions
CISA said it saw attacks on more than 100 internet-exposed water and wastewater systems in July, across at least 12 states. It is the first public count.
[21] Why it matters — The US then sanctioned six men it says hack for Iran's intelligence ministry.
[22] [23] -
07
Chrome fixed 327 flaws, most found by AI
Google's Chrome 152 patched 327 vulnerabilities, 299 of them found inside Google using AI. Ten were rated critical.
[24] Why it matters — Google has patched well over 2,000 Chrome flaws so far this year.
[24] -
08
Two more firms lose health and pay data
Nutex Health told the SEC that intruders copied files from its servers. Paylogix, which runs employee benefits, says passport numbers and medical data were taken.
[25] [26] Why it matters — The Paylogix files were stolen last November, and the notices are only reaching people now.
[26] -
09
Number-plate camera backlash reaches the Senate
Senator Josh Hawley opened an investigation into Flock Safety's camera data on Wednesday. A legal group's new database counts 93 local contracts ended.
[27] Why it matters — One Iowa county's policy tells officers not to mention the cameras in reports unless absolutely necessary.
[28] -
10
Android malware that works with no signal
ThreatFabric described Manic, Android malware that hands stolen data to nearby infected phones over Wi-Fi until one of them has internet.
[29] [30] Why it matters — It targets banking and government identity apps, mainly in Ukraine, and beats the idea that a disconnected phone is safe.
[29]
The best hiding place is the one nobody can afford to clear out
Camouflage is not always about looking different. Sometimes it means standing where the only way to reach the hider also reaches everybody else.
The twist
The camouflage is not the disguise. It is the bill somebody else would have to pay to remove it.
How it works
- The cheapest move against a hidden thing is a blunt one: block the road
- Blocking is only cheap while the road is empty
- So the hider moves onto a road that is full of other people
- Now the blunt move carries a price, and the hunter is the one who pays it
- What is left is slow, precise work, and the delay is the whole gain
Where you've seen this
Shared internet lines
cutting off one building's connection cuts off every flat inside it
Banking sanctions
the bank being punished also carries a whole country's ordinary wages
Junk email
blocking a mail provider stops the junk and everyone else's post with it
A chase through a crowd
called off not because the runner is fast, but because the street is full
The catch
Sometimes the hunter pays the bill anyway. Lumen blocked the rotating relays regardless, and says the block will not hold for long.
And the whole of it
The people whose connections carried this were reaching for an internet their own government had closed. Nobody told them they were the cover, and most of us sit in a system that has not told us either.
What is really going on
A state bought its spying from a private company and parked it inside ordinary people's internet traffic, and what got seized was a handful of domain names.
Why it works on us — A list of famous victims - NASA, the Federal Reserve, the Senate - makes a seizure sound like an ending, when the affidavit never says which of them were actually breached.
Who gains
-
Lumen
— an internet backbone provider gets public credit for a federal takedown built on its own network data.
[2] [4] -
Rival Chinese contractors
— the exposure is, in the tracking researcher's phrase, an egg-on-the-face moment for one supplier in a market with others.
[2] -
The Justice Department
— a named, dated result against Chinese hacking that needed no arrest and no extradition.
[1] [2]
Who pays
-
Chinese users of censorship-dodging VPNs
— their connections were the cover, and the relays carrying them were blocked at the backbone.
[2] [4] -
Owners of hacked routers and cameras
— their devices carried the traffic, and nothing announced this week cleans or notifies them.
[2] [4] -
Universities and research groups
— the researcher says the operators particularly liked research communities, which are built to share.
[3]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Which of the named agencies were actually breached, and how far the intruders got.
The affidavit lists targets and does not confirm outcomes.
[2] -
02
What eight years of collection was for.
Lumen says the targeting looks like broad information gathering rather than preparation to disrupt, but says that is only what it could see.
[2] -
03
How many ordinary VPN users lost their route out when the relays were blocked.
No figure appears in Lumen's analysis or in the reporting on the seizure.
[2] [4] -
04
Whether anything stops this restarting.
No person was charged, and the researcher who found it expects new infrastructure within weeks.
[2]
A company with no duty to look spent eighteen months tracking this, then handed what it found to people who could act on it. Patient attention like that is commoner than the news ever shows.
More from Cybersecurity
Across the beats