
One Story. Many Angles.
Western and Indian outlets detail US seizures and victims while Chinese coverage centers solely on official denial.
US and allied reporting converges on the technical details of domain seizures and victim lists drawn from court affidavits, treating the state-sponsorship link as established by the platforms’ client base. Chinese coverage, by contrast, opens with the embassy rebuttal and frames the episode as recycled political attacks without engaging the specific infrastructure claims. This divide shows how cyber attribution stories split cleanly along the US-China fault line: Western and Indian outlets relay DOJ statements and add context on prior operations against groups like Volt Typhoon, while the Sina account relays only the counter-narrative and Reuters framing of it. The Independent notes Beijing’s consistent denials but includes FBI Director Kash Patel’s quote on the botnet disruption; Al Jazeera and the Union Leader stay close to the announcement. The Times of India stands out by foregrounding enforcement mechanics and historical takedowns rather than blame. No independent chain verifies the Chinese firm’s client relationships or refutes them, leaving the core accusation resting on one reporting origin.
Perspective Analysis
The United States Justice Department announced on August 26, 2026, that it had seized domains linked to two hacking platforms, QScan and QTRouter, which authorities described as tools used by Chinese state-sponsored actors to compromise sensitive networks. The platforms had been active since at least 2018, according to court documents, enabling attackers to scan and infect thousands of internet-connected devices worldwide and then route malicious traffic through those compromised machines to obscure the origin of the activity. The Justice Department said the seizures rendered both platforms inoperable by removing hard-coded domains required for their communication and authentication functions.
The list of targeted entities included the Department of Justice itself, NASA, the Federal Reserve, the Senate, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the United States and South Korea. Specific incidents cited in the affidavit involved unsuccessful attempts against NASA networks in August 2019 and successful breaches at three Energy Department laboratories plus NIH and HHS networks in September 2024. The platforms were attributed to the China-based Nanjing Xinjiuwei Network Technology Company, whose paying clients were said to include China’s Ministry of State Security and the People’s Liberation Army.
Chinese officials responded through the embassy in Washington by rejecting the accusations outright. The embassy statement called the claims an effort to smear and discredit China and reiterated Beijing’s opposition to the politicization of cybersecurity issues, while pledging that China would continue to oppose and combat all forms of cyberattacks in accordance with its laws. The response echoed earlier Chinese diplomatic positions that have framed similar US statements as recycled allegations designed to justify restrictions on Chinese firms.
The platforms operated as a global botnet infrastructure. QScan automatically identified and infected internet-connected devices such as routers, folding them into a controlled network managed through QTRouter. This setup allowed attackers to make traffic directed at US targets appear to originate from devices in other countries or even near the target itself, buying time before attribution efforts could narrow the source. The Justice Department tied the infrastructure to a group it identified as QTFY, which offered hacking services to state customers.
US authorities framed the action as part of a broader pattern of operations against Chinese cyber activity. The affidavit and accompanying statements referenced earlier disruptions, including the 2025 removal of PlugX malware from more than 4,000 US computers linked to Mustang Panda, the 2024 takedown of a large network of compromised IoT devices attributed to Flax Typhoon, and the 2023 action against a botnet used by Volt Typhoon.
Reporting from outlets that carried the Justice Department announcement described the same core sequence of domain seizures and victim list. The Independent added context from cybersecurity analysts on the growth of Chinese private contractors offering offensive services to state agencies. The Times of India detailed the technical mechanics of the platforms and placed the operation in sequence with prior US actions against named Chinese groups. Al Jazeera noted the absence of immediate comment from the Chinese embassy or the Nanjing firm when contacted by Reuters. The Union Leader summarized the announcement as a national security breach involving the listed agencies.
Accounts diverge sharply on emphasis and framing. Outlets relaying the US statements foregrounded the operational details, the named platforms, the specific agencies compromised, and the history of similar takedowns. The Chinese account led instead with the embassy rebuttal and presented the episode as familiar political rhetoric without addressing the infrastructure claims or victim list. No reporting chain independent of the US affidavit verified the client relationships between Nanjing Xinjiuwei and Chinese intelligence or military entities, nor did any provide technical counter-evidence refuting the platform descriptions.
The corroborated elements across multiple independent reporting chains are the domain seizures, the platform names, the victim agencies, and the timeframe of activity beginning in 2018. These details appear consistently in court documents referenced by the Justice Department and carried by outlets that relayed the announcement. The attribution of the platforms to state sponsorship rests on a single reporting origin, the US affidavit, which multiple outlets transmitted without additional verification. The Chinese rejection stands as an on-record denial from the embassy, presented without engagement with the specific technical assertions.
What to Watch
This pattern of coverage indicates that cyber attribution disputes between the United States and China continue to produce parallel narratives rather than shared facts. The US side supplies primary documents that travel across Western and Indian reporting, while the Chinese side supplies diplomatic statements that travel within its own press. The absence of independent technical verification on either side leaves the core dispute unresolved in public reporting, with each account serving the institutional interests of the government that originated it. Future incidents of this type are likely to follow the same template, as the incentives for attribution and denial remain unchanged.
That’s how the world told the story.
Get tomorrow’s bulletin by email — one briefing, up to six stories.
Subscribe freeNo spam. One-click unsubscribe. See the latest email →
This bulletin was produced by The Intelligence Bulletin's autonomous editorial system under the editorial oversight of Rohit Sinnas, Founder & Editor-in-Chief. How it works →