# U.S. action against China-linked QTFY hacking platform

> Live situation record from CLSTR: https://clstr.news/situations/us-action-against-china-linked-qtfy-hacking-platform
> Updated: 2026-09-02T05:43:56.000Z. Sources: 25. Developments: 2.

U.S. federal authorities, including the Department of Justice and the FBI, seized core infrastructure and domains used by QTFY, a cyber platform linked to the Chinese firm Nanjing Xinjiuwei Network Technology Co. Investigators stated the platform utilized thousands of infected internet-of-things devices to facilitate espionage and attacks against U.S. government agencies and critical infrastructure, including NASA, the Federal Reserve, and the U.S. Senate.

Following the initial seizure, the Department of Justice provided clarifications regarding the scope of the group’s activities. While various institutions were targeted, officials noted that not all attempts were successful; for example, NASA prevented a breach through software corrections. However, confirmed intrusions were identified at certain Department of Energy national laboratories and health divisions. The Chinese embassy has contested these allegations, claiming the U.S. is using cybersecurity concerns to discredit the nation.

## Claims

- The Sality botnet has been active and infecting computers since 2003. (corroborated by 11 sources)
- The EggJagger payload stole at least $150,000 in cryptocurrency by swapping wallet addresses. (corroborated by 7 sources)
- Sality had distributed malicious payloads to more than 15,000 infected machines worldwide. (corroborated by 6 sources)
- The takedown was achieved by replacing trusted peers in the peer-to-peer network with sinkholes. (corroborated by 4 sources)
- The Sality botnet takeover was the most complex operation the company has ever conducted. (single source)
- Hackers began focusing on cryptocurrency theft using the botnet around 2017. (single source)

## Timeline

### 2026-09-02: Sality botnet dismantled in multinational cybercrime operation

International authorities and CrowdStrike have dismantled the Sality botnet, a Russia-based P2P network active since 2003 that used EggJagger malware to steal cryptocurrency via clipboard hijacking.

12 sources. https://clstr.news/cluster/us-authorities-dismantle-sality-botnet-and-disrupt-china-linked-hacking-group

### 2026-08-31: U.S. authorities seize domains used by Chinese-linked QTFY hacking platform

U.S. authorities have seized domains used by the Chinese-linked QTFY platform to target government agencies and critical infrastructure, including NASA and the Federal Reserve.

14 sources. https://clstr.news/cluster/us-authorities-seize-domains-used-by-chinese-hacking-group-qtfy

---
Cite as: U.S. action against China-linked QTFY hacking platform. CLSTR, https://clstr.news/situations/us-action-against-china-linked-qtfy-hacking-platform
