HomeFeaturedUS disrupts Chinese botnet network QTFY: From hacking, spies, propaganda to election interference, how...

US disrupts Chinese botnet network QTFY: From hacking, spies, propaganda to election interference, how China wages a shadow war against its rivals

The US authorities have announced the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target US critical infrastructure, reigniting concerns about China's global espionage activities.

China has long been running hacking campaigns against its friends and adversaries alike through its proxy networks for cyber espionage. The US authorities have detected and disrupted a major Chinese proxy network. On 26th August, the US Justice Department and the Federal Bureau of Investigation (FBI) announced the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target US critical infrastructure.

Chinese state-sponsored group QTFY created hacking platforms QScan and QTRouter to target US critical infrastructure

The hackers affiliated with the Chinese state-sponsored QTFY group were employed by Nanjing Xinjiuwei Network Technology Company, a China-based tech company. The QTFY group created and operated QScan and QRouter computer hacking services.

In a press release, the US Justice Department said, “The Justice Department and FBI announced court-authorised domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter.”

The US authorities claim that the cyber-espionage group QTFY offered computer hacking services to its paying customers, including the Chinese government’s Ministry of State Security and the People’s Liberation Army (PLA). These services included QScan and QTRouter.

“Payments from the PRC’s Ministry of State Security (MSS) to Nanjing Xinjiuwei, for example, indicate that the company conducts malicious cyber activities on behalf of the PRC Government,” the US authorities said.

First, QScan scans and automatically infects thousands of internet-of-things (IoT) devices globally, then these targeted IoT devices are added to the QTRouter network of QTFY-controlled devices.

Notably, an internet of things (IoT) device is any computing device accessible on the Internet, including home routers, security cameras, smart TV devices, smart appliances, etc.

The QTRouter comprises compromised IoT devices, commercial proxy service devices and leased virtual private servers.

The QTRouter then functions as an obfuscation network, allowing QTFY and related Chinese cyber-espionage actors to hide the Chinese origin of their computer intrusion activities “because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks.”

Since the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, “the court-authorized seizures made QScan and QTRouter inoperable,” the US Justice Department said.

Chinese state-sponsored QTFY cyber-espionage network included former PLA members

As per the US Justice Department and the FBI, the QTFY actors included former members of the Chinese military, the People’s Liberation Army. These ex-military personnel leveraged their PLA relationships to secure contracts and subcontracts supporting offensive cyber operations.

The QTFY network has been active since 2018 and has been used to compromise critical infrastructure in the US, including the Senate.

The targeted US institutions included the “National Aeronautics and Space Administration (NASA), Federal Reserve, Department of Energy (DOE), Department of Justice, Department of Health and Human Services (HHS), National Institutes of Health (NIH), and, in 2026, the Senate,” the court affidavit reads.

In addition, the QTFY network also targeted hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.

From cyber-espionage networks, spy recruitments, secret police stations, funding propaganda networks and election interference: How China serves its interests and weakens adversaries

From the 2025 Plug X surveillance malware removal by the FBI post-infection by the China-sponsored hacker group Mustang Panda, the 2024 Flax Typhoon group’s IoT infection for Chinese government customers, the 2023 Volt Typhoon network dismantlement to the now disrupted QTFY network, China has erected numerous cyber-espionage and hacking networks targeting critical infrastructure in the US and worldwide.

China’s tactics comprise a blend of human intelligence, cyber-espionage, and economic leverage to achieve its objectives.

The ruling Chinese Communist Party (CCP) has devised numerous tactics to further its interests on foreign soil and weaken its ‘adversaries’ from within.

Recently, it was reported that the British Royal Navy surveillance or spy drones used by elite special forces were found sending basic operating data to an IP address in China. The discovery was made during a routine cyber vulnerability assessment. Investigators found that cameras fitted to the drones contained some components made in China and were sending “heartbeat communications” to an IP address in the country. 

While the British authorities denied any leakage of sensitive information, the discovery created national security concerns because the drones had been used near the headquarters of the Special Boat Service (SBS) in Poole, Dorset.

Last year, British domestic security and counter-intelligence agency MI5 warned MPs that Chinese intelligence services were “relentless” in their efforts to interfere with and influence Parliament. The warning included concerns that employment websites such as LinkedIn could be used to collect sensitive information.

The warning came weeks after a case involving two men, including a parliamentary researcher accused of spying for China, collapsed. The case was affected by the Labour Government’s inability to describe Beijing as an enemy.

Back in 2020, the Conservative government ordered Huawei to be removed from Britain’s 5G network following security concerns.

In India, the Indian government banned around 59 Chinese apps, including TikTok, WeChat, and UC Browser, in 2020, after it emerged that some apps originating from China were stealing user information and sending it to Chinese servers. The Modi government said that these apps were banned as they “engaged in activities which are prejudicial to sovereignty and integrity of India, defence of India, the security of the state and public order”.

In April 2020, the Modi government effectively excluded Huawei from India’s 5G core networks and faced sustained restrictions on telecom contracts and equipment. 

Notably, Huawei has long been under the scanner globally over allegations that Huawei devices and equipment collect sensitive data of foreign countries and pass them to the CCP in China. In 2022, the FBI investigation found that Chinese-made Huawei equipment was capable of disrupting US nuclear arsenal communications.  Huawei equipment could not only intercept commercial call traffic but also critical communications made by the US Strategic Command via restricted airwaves.

In March this year, it was reported that India was pushing out Chinese CCTV makers including TP Link, Hikvision and Dahua out of the internet-connected camera market in the country. Back in 2021, the Indian government stated that around 10 lakh CCTV cameras installed in government institutions were sourced from Chinese companies. It acknowledged that video data captured through such devices could be transferred to servers located abroad, raising serious security concerns.

Beyond weaponisation of technology, China also relies on conventional spy recruitment methods. In early August 2026, it was reported that a former French Navy pilot, Pierre-Henri Chuet, came under formal investigation in France over allegations of passing sensitive military information to Chinese operatives.

Chuet made at least two undeclared trips to China in September 2018 and August 2019 while he was still serving in the French Navy. The trips were organised through the Test Flying Academy of South Africa (TFASA), a South African aviation company, which reportedly arranged training programs for Chinese military personnel.

The French Navy pilot under investigation had falsely claimed that during Operation Sindoor in May 2025, Pakistan’s Chinese-made fighter jets had shot down Indian Air Force (IAF) Rafales.

In September 2020, an Indian journalist, Rajeev Sharma, was arrested by a special cell of Delhi police under the Official Secrets Act for spying for China. Sharma was accused of passing sensitive information, including defence secrets, to Chinese intelligence. One Chinese woman and her Nepalese associate were also arrested for paying him large amounts of money routed through shell companies.

 In December 2020, Afghanistan arrested 10 Chinese citizens on charges of espionage and operating a terror cell in the capital city of Kabul. The accused were allegedly collecting information about Al-Qaeda to nab Eastern Turkestan Islamic Movement (ETIM) jihadis in Afghanistan, an internationally recognised terrorist group that China accuses of fomenting separatism in the Xinjiang Uyghur Autonomous Region (XUAR).

Back in February 2021, the UK media reported that the authorities had expelled three Chinese spies who had posed as journalists.

The MI5 concluded that the three worked for China’s Ministry of State Security (MSS) but had been using the cover of working for the country’s press agencies.

In July 2021, four Chinese nationals were charged in the US for being part of a Chinese global espionage campaign in which 12 countries including the US were targeted between July 2009 and September 2018.

 In July 2020, when the US was grappling with the COVID pandemic, the Trump administration accused Chinese citizens of stealing scientific research and told the country’s diplomats in Texas to leave. The former US Secretary of State, Mike Pompeo had then called the Houston Chinese consulate as a ‘hub of espionage activities”.

Recently, it was reported that secret email exchanges indicated that US health official colluded with scientist Peter Daszak to dismiss Wuhan lab leak theory about Corona virus’s Chinese origins.

China infiltrated corporates and foreign consulates for spying

In December 2020, it was reported citing the leaked CCP documents that the CCP through a recruitment agency executed a well-coordinated infiltration by getting its members employed in senior, specialist and advisory positions in consulates of countries such as India, UK, USA and Australia.

It must be recalled that Shaoquette Moselmane, an Australian MP was investigated in 2020 on charges of being a member of a global Chinese spy ring. Moselmane was highly pro-China and vocal about his inclination towards China. 

China infiltrated foreign academia

The CCP has long faced allegations of having concocted a spy ring at top US universities, including Boston and Harvard. China sends trained spies disguised as students, who are tasked with stealing intellectual property and research documents from the university labs and send it back to China. In many cases, these spies are Chinese military officials masquerading as ‘students’.

Interestingly, Chinese students form the second largest pool of international students studying in US universities after India. In May 2025, the Trump administration announced its plans to revoke the visas for Chinese students, including those having links with the Chinese Communist Party or studying in critical fields.

The US authorities discovered about the Chinese spy ring in the US academic ecosystem in 2020, following the arrest of Professor  Lieber, who was a research scientist at Harvard. Two Chinese spies posed as researchers were also charged as agents of a foreign government. The Chinese spies lied about their research work and used their access to smuggle research samples out of the US.

In October 2022, the US authorities indicted four Chinese nationals including three Ministry of State Security (MSS) intelligence officers for spying for China. The Chinese nationals, identified as Wang Lin, Bi Hongwei, Dong Ting, aka Chelsea Dong, and Wang Qiang, were entrusted to recruit individuals, particularly, professors, former law enforcement officials, state homeland security officials, for the Chinese government. 

In 2025, Greece arrested four Chinese nationals, two men, a woman, and a teenager near the Tanagra airbase for spying on Rafale fighter jets.

China’s secret police stations on foreign soil

In the recent years, intelligence agencies of various countries have raised alarms that China is running illegal police stations on foreign land in at least 21 countries on five continents. Countries such as Ukraine, Canada, Ireland, France, Spain, Germany, and the United Kingdom have such arrangements for Chinese police stations, and the leaders of the majority of these countries publicly question China’s rise and its deteriorating human rights records.

China has also been accused of using consulates and courts in other countries to suppress dissent against the CCP.

In January 2025, the Daily Caller News Foundation (DCNF) report found that China was imposing its legal system on American soil through a network of nonprofit organisations in the United States linked to a Chinese Communist Party (CCP) intelligence agency.

In December 2024, an American citizen pleaded guilty to involvement in operating a secret Chinese police station in Manhattan’s Chinatown.

Reports indicate that the CCP’s objective behind operating such illegal police stations is to suppress anti-China sentiments across the world, to spread communist ideology, bring back Chinese expats who violated Chinese law while abroad and to interfere in the governance and democratic processes of other countries.

Ashley Tellis, Neville Roy Singham and CCP’s narrative control network

For the CCP, narrative control both domestically and globally is crucial for clinging to power and furthering its interests. For authoritative regimes, the military is the main source of power and control; however, for the CCP, information/narrative is the key.

Be it suppressing the truth of the Tiananmen Square massacre to firewalling anti-government criticism, the CCP regime is of the view that its survival and unquestioned rule is contingent on narrative control. It is for this reason that the CCP has kept tight control over media, social media, public and private institutions, and even businesses.

China has cultivated assets in the US and other rival countries that not only extract sensitive information but also facilitate the CCP in maintaining a grip over how these countries and the perceives China.

In 2025, the US Department of Justice charged Ashley J. Tellis, a senior adviser to the U.S. State Department and a contractor with the Pentagon’s Office of Net Assessment, for espionage and unlawful retention of classified documents.

Tellis, notorious for peddling anti-India propaganda, is accused of removing sensitive military documents from secure facilities and meeting Chinese officials multiple times in Virginia between 2022 and 2023. Federal prosecutors allege that Tellis discussed “emerging technologies” and “Iran–China relations,” and was seen carrying manila envelopes and accepting gift bags from Chinese representatives.

Tellis’s modus operandi was also being replicated in India. In August 2023, The New York Times published an explosive exposé revealing that Neville Roy Singham, an American millionaire “working closely with the Chinese Communist Party’s media machine,” was funnelling money to NewsClick, a far-left Indian portal.

Delhi Police chargesheet filed in 2024 described the Chinese state as the “ultimate paymaster”, with funds routed to stoke anti-India narratives, especially regarding Kashmir, and farmers’ protests. The case is ongoing in the court.

In 2021, OpIndia published an investigative report on the links of NewsClick and uncovered how it was linked to several individuals who regularly spew venom against India, from Urban Naxals to those like Teesta Setalvad, Abhisar Sharma and several others. 

That investigation by OpIndia can be read here.

OpIndia previously reported about how the CCP created a transnational network of non-profits, activist groups, think tanks, and media outlets, operating as its propaganda machinery. The CCP orchestrated a pro-China information laundering network helmed by Neville Roy Singham, the US-born tech tycoon who sold his IT consulting firm Thoughtworks for about $785 million in 2017 before relocating to Shanghai.

This information laundering network erected at the CCP’s behest modifies raw activism into polished propaganda, which is then amplified by the Roy-Singham-funded network to sow discord in the US and other democracies while burnishing China’s image as a ‘benevolent’ counterweight to ‘imperialism’, particularly American imperialism, with the ongoing left-wing activism in Cuba being a textbook case of this.

From pro-Palestine activism in the US, influx of far-left activists in Cuba amidst President Trump’s rising interest in the country, to ‘No War’ activism over the Iran war, these seemingly spontaneous and genuine anti-war protests are in reality, a part of well-organised, well-funded, and politically-motivated campaign, orchestrated by organisations and activists all finding their roots in the Neville Roy Singham’s network of philanthropic organisations, think thanks, media, and activists, intellectuals, celebrities, political organisers and comrades.

As reported earlier, Neville Roy Singham funnelled over $278 million directly into his pro-China propaganda network since 2017, with total money flows exceeding $591 million across 223 transactions spanning five continents through the year 2025. The massive amount was pumped into over a thousand interconnected organisations, of which around 200 are directly involved in creating and propagating pro-China and anti-America messaging at the CCP’s behest.

China’s foreign election interference

For years, China has been accused of meddling in and influencing elections in several countries through numerous tactics. In mid-July 2026, US President Donald Trump declassified and publicised several intelligence and law enforcement documents from 2020, alleging that China acquired 200 million American voter data and exploited vulnerabilities in the US election system to influence the poll in Joe Biden’s favour.

China has also been accused of meddling in Canadian elections. In June 2024, a Canadian intelligence watchdog, the National Security and Intelligence Committee of Parliamentarians (NSICOP), released a report titled: Special Report on Foreign Interference in Canada’s Democratic Processes and Institutions. It uncovered the extensive interference of China in Canada’s electoral and legislative affairs. The redacted report mentions how certain Canadian MPs colluded with China.

The report also mentioned the CCP’s alleged illegal attempts to intervene in Canadian elections, bribing Canadian officials, and using covert techniques to exploit Canada’s indigenous people for resource extraction, as mentioned in the non-redacted 2019 version of the report.

The NSICOP report stated that China used social media alongside the legacy media to influence the opinions of Canadian voters, ethnocultural groups and parliamentarians.

During the 2021 federal election in Canada, the Security and Intelligence Threats to Elections Task Force (SITE) noted that mainstream media and social media activities aimed at discouraging voters from supporting the Conservative Party. While a direct link to the Chinese government did not emerge, the pattern indicated a coordinated campaign orchestrated by China.

In addition to Canada, China has also weaponised social media to influence elections in India and the US. In 2023, Facebook’s parent Meta revealed that it took down a network of 4789 China-based fake and misleading accounts. These accounts were created with the purpose of propagating misleading information about sensitive issues related to US politics, US-China relations, and Indian politics.

While China obviously denies any wrongdoing, there is a clear pattern of the CCP’s covert and sinister activities to undermine its perceived adversaries and rivals.

Join OpIndia's official WhatsApp channel

  Support Us  

For likes of 'The Wire' who consider 'nationalism' a bad word, there is never paucity of funds. They have a well-oiled international ecosystem that keeps their business running. We need your support to fight them. Please contribute whatever you can afford

Shraddha Pandey
Shraddha Pandey
Senior Sub-Editor at OpIndia. Email: [email protected]

Related Articles

Trending now

- Advertisement -