SAN DIEGO — A sworn FBI affidavit unsealed Wednesday describes a seven-year investigation into a Chinese hacking operation that targeted NASA, the Federal Reserve, the Department of Energy, the Justice Department, the National Institutes of Health and, this year, the United States Senate.
The filing says payments from China’s Ministry of State Security to Nanjing Xinjiuwei Network Technology Co. indicate that the private company conducted malicious cyber operations for Beijing. Some of its hackers were former members of the People’s Liberation Army who used their military connections to obtain contracts and subcontracts for offensive cyber operations.
But the targets went far beyond Washington.
According to the affidavit, the same infrastructure was used against hospitals, telecommunications carriers, power companies, financial institutions and defence contractors in the United States and abroad.
Its reach also extended into ordinary homes and businesses. The hackers exploited internet-connected routers, security cameras, televisions and appliances without their owners’ knowledge, then used the captured devices to support further attacks. On a single day in 2024, one component of the system processed more than two million scanning and exploitation tasks.
The system had two main parts.
QScan searched the internet for vulnerable equipment and attempted to break into it automatically.
QTRouter then concealed where the attacks originated. It routed traffic through compromised devices, rented servers and commercial proxy services, allowing an operation directed from China to appear to come from a device close to its intended victim.
Nanjing Xinjiuwei used the system itself and sold access to other operators.
The affidavit does not mention Canada or motor vehicles. Its relevance to Ottawa lies in the vulnerability the FBI exposed: everyday equipment connected to the internet can be discovered, exploited and turned to another purpose without its owner knowing.
Under Prime Minister Mark Carney’s January agreement with Beijing, Canada opened an annual quota of 49,000 electric vehicles originating in China, repealing the 100 per cent surtax and leaving the 6.1 per cent most-favoured-nation tariff. By August 21, 15,063 vehicles—more than 61 per cent of the first six-month allocation of 24,500—had been counted against the quota. The quota is based on country of origin, not brand, so China-built vehicles sold under Western marques can qualify alongside Chinese brands.
A modern electric vehicle contains cellular connections, cameras, microphones, navigation systems and dozens—or even hundreds—of computers that receive software updates from outside servers.
Researchers with Norway’s Project Lion Cage explicitly treat smart vehicles as part of the broader IoT threat environment. The project examines how everyday connected technologies, including vehicles and other IoT systems, could be exploited during a future security crisis.
A team of about 10 experts led by Tor Indstøy, vice-president of risk management and threat intelligence at Telenor Group, and Arild Tjomsland of the University of South-Eastern Norway spent two and a half years collecting data from a Chinese-built NIO ES8.
According to the project’s leaders, a white-hat hacker required only four days to penetrate the vehicle’s systems.
The Lion Cage project also found that the vehicle communicated constantly, including when it appeared to be switched off. The traffic volume changed little over the course of a day or when the vehicle was isolated in a mine beneath Sandvika, outside Oslo.
The researchers reported that 70 per cent of its data packets used a heavily encrypted protocol they could not identify and that 90 per cent of its traffic was routed to China. The vehicle had seven eight-megapixel cameras, which NIO advertises as capable of recognizing a person at 223 metres.
Could the car be used as a data-collection platform? The team answered yes.
Could it be used to sabotage traffic? “Yes. And by anyone,” the researchers concluded. “Cybersecurity is below standard.”
At the Brussels Economic Security Forum, Indstøy placed the issue on a national scale. Norway, he said, already had approximately 77,000 Chinese-made cars on its roads, concentrated heavily in major cities.
Project Lion Cage assessed that, if their connected systems were exploited, those vehicles could form a “rolling surveillance network” more capable than any individual intelligence operative carrying a laptop or phone.
Thousands of moving cars equipped with cameras, microphones, location systems and cellular connections could repeatedly encounter the same people, attach faces to times and locations, and combine sightings collected across a city.
The researchers identified the most likely targets as Chinese dissidents, students and researchers; employees and subcontractors working in critical industries and infrastructure; and Norwegian persons of interest capable of influencing relations with China.
The FBI investigation began in August 2019, when hackers twice attempted to exploit a vulnerability in a remote-access appliance protecting a NASA server. NASA had already installed the available security patch, and the attempts failed.
Subscriber records showed that the internet address used in the attack had been leased through an account registered to a man in Changsha, China, and linked to two Gmail addresses. Search warrants served on Google in November 2020 and January 2021 uncovered five connected accounts. Shared recovery addresses and Google tracking cookies showed that some were being accessed by the same user.
Those accounts contained years of complaints from organizations being attacked through servers the hackers had leased.
In August 2020, an Ohio medical centre reported that its remote-access equipment was being targeted through the same vulnerability used against NASA. Its message to the hosting company was blunt: “Attacking healthcare in a pandemic is just wrong.”
A South Korean financial institution complained twice that its network was classified as a top-tier national-security facility and warned that the scanning would be treated as an attack on critical infrastructure. A Michigan financial group identified eight addresses used against it over four weeks. A Missouri insurance agency reported an attempt to exploit its Citrix equipment.
By 2024, the operation could move almost immediately when a new vulnerability became public.
In May of that year, only days after a flaw in a Check Point security gateway was disclosed, the group exploited it and stole server-configuration files and user-account information from more than 300 organizations in the United States. Three victims were located in the Southern District of California.
That September, the same group used a previously unknown vulnerability in an Ivanti appliance to enter three Department of Energy national laboratories, the National Institutes of Health, another Health and Human Services agency and an American security-device manufacturer.
Investigators traced the access to one internet address. The following month, one of the domains the government has now seized pointed to that same address.
The legal route used to seize the domains was money laundering.
Federal law permits the forfeiture of property purchased through an international transfer of money intended to promote certain crimes, including attacks on protected computers. The government argued that payments used to register the domains travelled from China into the United States and helped sustain the hacking operation.
In February 2022, a QTFY-controlled account paid $85.70 through PayPal to register qt-team.com with a company in Phoenix. The transaction came from a China Telecom address in Jiangsu and used an Agricultural Bank of China debit card.
That November, another account paid $43.83 to register qtproxy.xyz. Although the payment came through an internet address located in Taiwan, subscriber and payment records tied it to a Chinese address, cellphone number, name and Agricultural Bank of China card.
In December 2025, qt-proxy.org was registered through an Alipay transaction made from a Hong Kong internet address. The payment was cleared through a gateway headquartered in New York.
The three domains—qt-team.com, qtproxy.xyz and qt-proxy.org—were built directly into QScan and QTRouter. The Justice Department said their seizure disabled both systems.
The department placed Wednesday’s action alongside three earlier operations: the disruption of a Volt Typhoon botnet in 2023, a Flax Typhoon network containing hundreds of thousands of compromised devices in 2024, and the removal of Mustang Panda malware from more than 4,000 American computers in 2025.



