← Home
TECH NEWS

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

September 1, 2026 Hannah Osei

The disruption involved seizing command-and-control servers and cutting off communication channels used by the malware

The US government announced on Wednesday that it has disrupted a hacking platform and botnet operated by a group known as QTFY, which provides cyber intrusion services to the Chinese government and other clients. The operation, conducted in coordination with international partners, targeted infrastructure used to launch attacks against military networks and critical infrastructure systems globally. Authorities said the takedown significantly degraded the group’s ability to conduct espionage and disruptive cyber campaigns. QTFY has been linked to a series of intrusions targeting defense contractors, energy providers, and telecommunications firms across multiple continents. The platform reportedly offered hacking-as-a-service tools, including malware distribution and remote access capabilities, enabling clients to breach secure networks. Investigators said the botnet had been active for several years, leveraging compromised devices to mask the origin of attacks.

The disruption involved seizing command-and-control servers and cutting off communication channels used by the malware. How the Takedown Was Executed Law enforcement and cybersecurity agencies worked together to map the botnet’s infrastructure, identifying key nodes in Europe and Asia that routed malicious traffic. By coordinating with internet service providers and hosting companies, authorities were able to isolate and disable servers without causing widespread collateral damage. Officials noted that the operation relied on legal processes in multiple jurisdictions to ensure evidence was preserved and actions were defensible in court. The effort marks one of the most coordinated takedowns of a state-linked cyber service to date. What Does This Mean for Future Cyber Threats? While the disruption is a significant blow to QTFY’s operations, experts warn that similar platforms may reemerge under different names or structures.

The group’s ties to state actors suggest that replacement services could emerge quickly

The group’s ties to state actors suggest that replacement services could emerge quickly, especially if demand for deniable cyber capabilities remains high. Officials emphasized that sustained pressure, including sanctions and public attribution, will be necessary to deter future abuse. They also urged organizations to strengthen defenses against known tactics used by such platforms. Frequently Asked Questions What is QTFY and what services did it provide? QTFY is a hacking group that offered cyber intrusion tools and access to compromised networks as a service, primarily to clients linked to the Chinese government. Its platform enabled espionage and disruption campaigns targeting military and critical infrastructure sectors.

How did the US disrupt the platform? Authorities seized command-and-control servers, severed communication channels used by the botnet, and coordinated with global partners to disable infrastructure across multiple countries. The action was based on legal processes in several jurisdictions to ensure legitimacy.

Is the threat completely eliminated? No, while the current infrastructure has been disabled, officials caution that similar services could reappear under new names. Continued vigilance and international cooperation are seen as essential to counter evolving cyber threats.

Read full article on Tech Site News →