PRC state-backed 'QTFY' hacking ring burrows into US federal agencies and critical infrastructure
- Unsealed court records reveal Chinese state-sponsored hackers breached NASA flight centers, the U.S. Treasury, and the Senate.
- Operated through a Nanjing-based commercial tech contractor (Xinjiuwei) serving as an operational cutout for the Ministry of State Security.
- Primary targeting prioritized space propulsion, aerospace telemetry, and financial settlement networks over routine diplomatic channels.
China’s civilian front companies are back in the dock. According to unsealed Department of Justice indictments reported by CyberScoop, contract hackers operating under a Nanjing-based tech firm called Xinjiuwei breached NASA flight research centers, the U.S. Treasury, and major commercial banking networks. The contractor operated as an operational arm of the Ministry of State Security. Under the codename QTFY, operators tunneled through enterprise VPN appliances, deployed custom webshells, and spent months siphoning telemetry on space propulsion and aerospace blueprints.
The operation is a textbook use of commercial front cutouts for pretextual cloaking. Beijing has run this play for years, mirroring previous DOJ indictments against Hainan Xiandun and Chengdu-based shells. Setting up commercial front companies gives state intelligence a layer of plausible deniability. The Ministry of State Security directs the intrusions from behind a corporate facade, protecting central party leadership from diplomatic fallout whenever an operation blows up.
The target list reveals the real objective: critical infrastructure pre-positioning. Intruders skipped routine embassy correspondence to dig deep into financial settlement engines and civilian space architectures. Those footholds give Beijing disruptive leverage long before a shot is fired. When state operators burrow into foreign public utilities, peacetime espionage quietly transforms into wartime sabotage.
Discussions regarding the Nanjing Xinjiuwei corporate registry surfaced briefly on V2EX and tech-focused Zhihu threads before deletions; programmers noted the company abruptly dissolved its business registry and vacated its office space.
State media completely suppressed the DOJ indictment; search queries for the front company 'Xinjiuwei' were throttled on Baidu and Weibo under Cyberspace Administration of China (CAC) directives.
Xinjiuwei operated under the tasking of the MSS Jiangsu State Security Department, the same unit previously indicted in 2018 for aerospace corporate espionage targeting GE Aviation.