FBI, NSA Dismantle China-Linked Hacking Network Targeting NASA, Federal Reserve
The U.S. Federal Bureau of Investigation and National Security Agency have dismantled a China-linked hacking operation targeting American critical infrastructure and sensitive networks. The two agencies announced the…
The U.S. Federal Bureau of Investigation and National Security Agency have dismantled a China-linked hacking operation targeting American critical infrastructure and sensitive networks.
The two agencies announced the operation on Wednesday, with the Justice Department and FBI stating they seized domains used by the QTFY platform, including QScan and QTRouter. The NSA, FBI, and Cyber National Mission Force also jointly released a cybersecurity advisory detailing the group's activities since 2018.
"Today we announce the dismantling of a global botnet and hacking platform used by China-state-sponsored hackers to target U.S. critical infrastructure," said FBI Director Kash Patel in a Justice Department statement. "These tools were used by Chinese state-sponsored actors to hide the sources of their attacks. We thank the FBI San Diego field office, the FBI's cyber division, and our Justice Department partners for their work in seizing adversary infrastructure and shutting down these platforms."
How QTFY Hid Its Attacks
U.S. authorities linked QTFY to Nanjing Xinjiuwei Network Technology Company, headquartered in Nanjing, China. Investigators said the group used QScan to scan and exploit vulnerable internet-connected devices, and QTRouter to conceal the origins of their attacks.
According to court documents, QTFY provided hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army. The QTRouter network consisted of compromised IoT devices, commercial proxy services, and leased virtual private servers.
The FBI affidavit stated that QTFY activities targeted U.S. government and critical infrastructure networks, including NASA, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. It also described a 2019 intrusion into NASA and a 2024 attack involving three Department of Energy laboratories.
According to the affidavit, QScan processed over 2 million scanning and exploitation tasks in 2024. Investigators also said QTFY exploited a vulnerability to steal server configuration files and user account data from more than 300 U.S. organizations.
The FBI said the seized domains were critical to the operation of QScan and QTRouter, and the Justice Department stated that taking control of these domains rendered the platforms inoperable.
China-Linked Cyber Threats
The latest action comes amid growing U.S. concern over China-linked cyber activities. CrowdStrike Holdings previously found that over 58% of state-sponsored cyberattacks targeting technology companies originated from China-linked actors, who sought artificial intelligence technology and intellectual property.
Separately, researchers at the Israeli cybersecurity firm Dream reported a July campaign targeting Taiwan's government systems that compromised at least 85 accounts and exfiltrated over 2,500 personnel records. The researchers said the operation showed indications of China-linked activity.
JPMorgan Chase & Co. CEO Jamie Dimon has also supported efforts to improve cooperation between companies on cybersecurity and critical infrastructure risks, citing the growing threat from cyberattacks and advanced artificial intelligence.
QTFY's Additional Concealment Methods
According to a Wednesday report in The Wall Street Journal, the operation also used so-called Chinese "airport" networks to mix malicious traffic with normal internet activity.
Rumaisa Habib, a Stanford University doctoral student who studied these networks, told The Wall Street Journal that thousands of such networks operate in China and are promoted via Telegram.
Damon Rouse, an engineer at Black Lotus Labs, told The Wall Street Journal that this method gives attackers "plausible deniability," making them harder to identify.
"State-sponsored malicious hackers targeting U.S. critical infrastructure will be stopped and prosecuted," said Attorney General Todd Blanche in the Justice Department statement. "We are here to ensure the safety of the American people and will use every tool at our disposal to fulfill this commitment."
"Today's announcement demonstrates the Justice Department's firm commitment to proactively countering cyber threats to national security," said Assistant Attorney General for National Security John A. Eisenberg. "These court-authorized seizures have denied Chinese state-sponsored hackers access to the tools they used to launch online attacks against our critical infrastructure."
The Justice Department said the dismantling of QTFY is part of a broader series of actions against China-backed hacking networks. The FBI and NSA also released compromise indicators to help organizations identify related activity.
Original: https://www.benzinga.com/markets/tech/26/08/61454568/china-linked-qtfy-hacking-network
insigtX content is informational and educational, not investment advice.