China Hacked NASA. Your Router May Have Helped.

By  
Gigabit Systems
August 30, 2026
20 min read
Share this post

China Hacked NASA. Your Router May Have Helped.

The hackers didn’t need their own infrastructure. They borrowed ours.

NASA.

The Federal Reserve.

The Department of Justice.

The Department of Energy.

The Department of Health and Human Services.

The National Institutes of Health.

The United States Senate.

Hospitals.

Financial institutions.

Power companies.

Defense contractors.

According to the U.S. government, Chinese state-sponsored hackers have spent years attacking some of America’s most sensitive networks.

This week, the Justice Department and FBI announced that they had disrupted two of the platforms allegedly helping them do it:

QScan and QTRouter.

And buried underneath the spectacular list of government targets is a cybersecurity lesson every small business should understand.

The infrastructure used to hide these attacks wasn’t necessarily sitting inside some secret Chinese intelligence facility.

It included ordinary compromised devices scattered around the world.

Routers.

Security cameras.

Other Internet of Things equipment.

Potentially the same kinds of devices sitting inside millions of American businesses right now.

First, Meet QScan

According to the Justice Department, a China-based group known as QTFY operated QScan.

QScan essentially searched the internet looking for vulnerable IoT devices.

When it found exploitable equipment, it could automatically compromise those devices.

Thousands of infected devices could then be fed into the second part of the operation:

QTRouter.

Now things get considerably more interesting.

QTRouter Made China Look Like Your Neighborhood

Imagine I’m sitting in China and want to attack an organization in New York.

If I connect directly from China, defenders might immediately become suspicious.

They see:

Login from China.

Block.

Investigate.

Alert the SOC.

So instead, imagine I’ve compromised a router inside a completely unrelated American business.

I route my attack through that router.

The target doesn’t necessarily see:

Attacker in China.

It sees:

Traffic coming from somewhere in America.

Potentially somewhere very close to the victim.

That’s essentially the purpose of an obfuscation network.

The Justice Department says QTRouter combined compromised IoT devices with commercial proxy devices and leased virtual private servers to conceal the Chinese origin of malicious activity.

The FBI says compromised equipment existed across more than 130 countries.

The hacker is thousands of miles away.

The attack appears to be coming from down the street.

That’s an Extremely Powerful Cybersecurity Weapon

Security systems use context.

Where is this connection coming from?

Has this IP address been malicious before?

What country is it in?

Does the geography make sense?

Is it associated with a hosting provider?

Is it a known VPN?

Is it a residential ISP?

Attackers understand those controls.

So they disguise themselves.

A compromised router inside a legitimate American network gives an attacker something valuable:

Reputation.

The IP address may not look malicious.

The geography may not look suspicious.

The device may have existed there for years.

Nobody bought infrastructure specifically for the attack.

Nobody necessarily noticed anything strange.

It’s someone else’s equipment.

That’s why compromised routers and IoT devices have become such useful infrastructure for sophisticated attackers.

Now Look at Who They Targeted

According to court documents, QTFY’s activity dates back to at least 2018.

Targets and victims identified by U.S. authorities included NASA, the Federal Reserve, DOJ, DOE, HHS, NIH and the U.S. Senate, along with organizations in critical infrastructure and the private sector.

Reuters reports that investigators traced an attempted 2019 NASA intrusion involving exploitation of a Pulse Secure VPN vulnerability back to infrastructure and accounts connected to China.

The campaign continued for years.

The FBI was still investigating activity connected to an attack targeting the U.S. Senate in 2026.

Think about that timeline.

  1. 2018.

  2. 2019.

  3. 2020.

  4. 2021.

  5. 2022.

  6. 2023.

  7. 2024.

  8. 2025.

  9. 2026.

Cyber espionage isn’t necessarily somebody smashing through your firewall one night.

Sophisticated campaigns are infrastructure businesses.

Attackers build systems.

Maintain access.

Develop tools.

Acquire vulnerable devices.

Build proxy networks.

Sell services.

Replace infrastructure that gets discovered.

Then keep operating.

This Was Apparently a Business Too

This is another fascinating part.

The Justice Department alleges QTFY works through a Chinese company called Nanjing Xinjiuwei Network Technology Company.

According to U.S. authorities, the company offered hacking services to paying customers—including China’s Ministry of State Security and People’s Liberation Army.

Think about what that means.

We sometimes picture nation-state hacking as government employees sitting inside military buildings.

Modern cyber operations can be much messier.

Private contractors.

Hackers-for-hire.

Government customers.

Commercial infrastructure.

Stolen infrastructure.

Compromised consumer equipment.

Proxy services.

Botnets.

It’s an ecosystem.

The FBI described the company as operating within a complex network of hackers-for-hire and government customers.

Cybercrime and cyber espionage have supply chains too.

So How Did America Shut It Down?

This part is wonderfully simple.

The FBI didn’t need to find every compromised camera and router around the world.

Investigators identified something the system depended upon:

Three domain names.

According to the FBI affidavit, they were:

qtproxy.xyz

qt-proxy.org

qt-team.com

Those domains performed essential functions for QScan and QTRouter, including communication and authentication.

The government obtained court-authorized seizure warrants.

Then it seized them.

And because those domains were hard-coded into the platforms, DOJ says the seizures rendered QScan and QTRouter inoperable.

That’s a beautiful incident-response lesson.

You don’t necessarily have to destroy every component of an attack.

Find what the system depends on and break that dependency.

Your $80 Router Can Become Part of a Nation-State Operation

Here’s where this stops being a Washington story.

Imagine you run a 25-person business.

You have:

A firewall.

Three wireless access points.

Six security cameras.

A network video recorder.

Two smart TVs.

A door-access controller.

A printer.

A thermostat.

A conference-room system.

Maybe an old router installed by a vendor six years ago.

Which of those devices are being patched?

Who manages them?

What firmware versions are running?

Are default credentials still configured?

Can they be reached from the internet?

Do they have unnecessary remote-management services enabled?

Does your MSP even know they exist?

If you can’t answer those questions:

Neither can your cybersecurity program.

IoT Devices Are Computers

Businesses don’t think about them that way.

That’s the problem.

A security camera looks like a camera.

A printer looks like a printer.

A thermostat looks like a thermostat.

A router looks like an appliance.

But increasingly they’re all:

Computers connected to your network.

They have:

Operating systems.

Processors.

Memory.

Passwords.

Network services.

Firmware.

Cloud connections.

Remote-access capabilities.

Vulnerabilities.

And sometimes extraordinarily poor security.

The attacker doesn’t care that you call it a camera.

They see a Linux computer connected to the internet.

This Is Why Asset Inventory Matters

Here’s a cybersecurity exercise every SMB should perform.

Ask your MSP:

“Show me everything connected to my network.”

Not just Windows computers.

Everything.

Laptops.

Servers.

Phones.

Printers.

Cameras.

Access points.

Switches.

Firewalls.

Door controllers.

HVAC equipment.

Conference-room systems.

Smart TVs.

IoT devices.

Vendor equipment.

Unknown devices.

Then ask:

“Which of these are we actually responsible for securing?”

That second question usually gets more interesting.

Find the Forgotten Equipment

Some of the riskiest technology inside a business isn’t new.

It’s forgotten.

The camera installer put something in five years ago.

The HVAC contractor installed a gateway.

The phone vendor left a box.

The previous MSP installed a router.

Nobody remembers the password.

Nobody knows whether firmware updates exist.

Nobody knows whether the manufacturer still supports it.

But it’s still:

Powered on.

Connected.

Talking to the internet.

Attackers love forgotten technology.

Because defenders aren’t watching it.

Cameras Deserve Special Attention

Security cameras are particularly interesting.

Companies install them specifically to improve physical security.

Then forget that they’re network devices.

Check:

Are they segmented from employee computers?

Can they reach the internet?

Can the internet reach them?

Are default passwords gone?

Is remote access enabled?

Is firmware supported?

Who has administrator access?

Does the installer still have access?

Where does footage go?

What cloud services are involved?

If your camera gets compromised, the problem isn’t merely somebody potentially watching it.

It can become somebody else’s computer inside your network.

That’s a much bigger problem.

Stop Exposing Things Directly to the Internet

This lesson keeps appearing across cybersecurity incidents.

If something does not need to accept unsolicited connections from the public internet:

Don’t let it.

Especially:

Routers.

Cameras.

NAS devices.

Remote-management interfaces.

Industrial controllers.

Building automation.

Old VPN appliances.

Remote Desktop.

Internet-connected storage.

Reduce the attack surface.

Use secure remote-access architectures.

Patch internet-facing equipment aggressively.

Replace unsupported devices.

Disable unnecessary services.

Segment IoT networks.

Monitor outbound connections.

Use strong unique credentials.

And where supported, enable MFA.

Basic cyber hygiene becomes extremely powerful when performed consistently.

Network Segmentation Matters Here Too

Imagine an attacker compromises your security camera.

What can that camera reach?

If the answer is:

Employee laptops.

Servers.

Accounting systems.

Backups.

Domain controllers.

Printers.

Everything.

You have another problem.

IoT equipment should generally live on networks appropriate to its function, with tightly controlled communication to other environments.

Your cameras don’t need to talk to accounting.

Your guest Wi-Fi doesn’t need to reach your server.

Your smart television doesn’t need access to your backup infrastructure.

Your thermostat doesn’t need to communicate with employee laptops.

Make attackers cross walls.

Don’t hand them a flat network.

Geographic Blocking Isn’t Enough

This attack also demonstrates an important limitation of country blocking.

I like geographic restrictions where appropriate.

If your 30-person New York business has no employees, customers or vendors in certain countries, there may be very little reason to accept authentication attempts or remote-management traffic from them.

That’s useful.

But don’t confuse it with complete protection.

Because sophisticated attackers know exactly what you’re doing.

They route through:

Compromised American routers.

Residential proxies.

Cloud infrastructure.

VPNs.

Other victims.

The attacker can be sitting in Beijing while your firewall sees:

New Jersey.

That’s why cybersecurity can’t rely on IP geography alone.

Identity.

Device health.

Behavior.

MFA.

Conditional Access.

Least privilege.

Endpoint security.

Logging.

Those layers matter.

This Is Also Why “Trusted IP” Can Be Dangerous

Businesses love allowlists.

This IP address belongs to our vendor. Trust it.

Be careful.

IP addresses aren’t identities.

Infrastructure gets compromised.

Credentials get stolen.

Cloud systems change.

VPN exit points get abused.

A request coming from an expected network location does not automatically mean:

The expected human generated it.

Modern Zero Trust architecture is built around exactly this assumption:

Don’t trust something simply because of where it came from.

Verify.

The Government Didn’t End Chinese Cyber Espionage

Another important distinction:

The FBI disrupted these platforms.

That doesn’t mean the underlying threat disappeared.

The seized domains were important enough that DOJ says QScan and QTRouter became inoperable.

That’s significant.

But sophisticated threat actors rebuild.

New domains.

New malware.

New exploits.

New proxies.

New compromised devices.

New contractors.

This is why cybersecurity isn’t a project you finish.

It’s an operating function.

We’ve Seen This Movie Before

This isn’t even the first time the FBI has disrupted Chinese state-backed infrastructure built from other people’s compromised devices.

In 2023, the FBI disrupted a botnet used by Volt Typhoon to conceal attacks against critical infrastructure.

In 2024, authorities disrupted infrastructure involving hundreds of thousands of compromised IoT devices associated with Flax Typhoon.

In 2025, the FBI removed PlugX malware from more than 4,000 U.S. computers associated with the China-linked Mustang Panda operation.

And now:

QScan and QTRouter.

There’s a pattern here.

Other people’s vulnerable devices are useful national-security infrastructure.

Make sure yours aren’t among them.

Cybersecurity Isn’t Just About Protecting Your Data

This is the bigger lesson.

Most business owners think cybersecurity means:

Protect my company from being hacked.

That’s obviously important.

But an insecure device can create another problem.

Your infrastructure can be weaponized against somebody else.

Your router.

Your camera.

Your server.

Your compromised cloud account.

Your website.

Your email.

Your IP address.

Suddenly your company isn’t necessarily the ultimate target.

You’re infrastructure.

That’s why patching a forgotten router matters even if there’s “nothing important on it.”

The attacker may not want what’s inside the router.

They want where the router is.

A legitimate American IP address.

A foothold.

A proxy.

A place to hide.

And according to the U.S. government, Chinese state-sponsored hackers built an entire operation around exactly that idea.

NASA and the Federal Reserve make spectacular headlines.

But the cybersecurity lesson is sitting somewhere much closer to home:

That forgotten camera or router in the corner isn’t too insignificant for a nation-state hacker.

It might be exactly what they’re looking for.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ManagedIT #IoTSecurity #DataProtection #SMB


China hacked NASA and the Federal Reserve by hiding behind ordinary routers and cameras. Is yours patched?

Share this post
See some more of our most recent posts...