Washington: Chinese state-sponsored hackers used two platforms to target NASA, the Federal Reserve, the Justice Department, and the US Senate, according to court documents unsealed Wednesday. The hackers also targeted the Energy Department, Department of Health and Human Services, and National Institutes of Health, said the Justice Department.
According to Anadolu Agency, US authorities seized three domains used by the QScan and QTRouter platforms, rendering both systems inoperable. The platforms were allegedly created and operated by a Chinese-based group known as QTFY, which worked for the Nanjing Xinjiuwei Network Technology Company. This company reportedly carried out malicious cyber activities on behalf of the Chinese government and received payments from the Ministry of State Security, as noted in an FBI affidavit filed in the Southern District of California.
QTFY allegedly offered hacking services to customers, including the Ministry of State Security and the People's Liberation Army. QScan was used to scan the internet for vulnerable devices, automatically infecting thousands worldwide. These compromised devices were then added to QTRouter, a network that allowed hackers to conceal the origin of their attacks. By routing malicious traffic through infected devices near their targets, the hackers could make attacks appear to originate from legitimate local users, explained the affidavit.
In addition to federal agencies, the group also targeted hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The FBI investigated an attempted intrusion by QTFY into NASA's network in 2019, which failed because NASA had already patched the vulnerability the hackers sought to exploit.
US Attorney General Todd Blanche stated that the operation successfully disabled the Chinese state-sponsored malicious software. FBI Director Kash Patel described the action as the disruption of a "global botnet and hacking platform." Furthermore, the FBI and National Security Agency released a cybersecurity advisory concerning QTFY activity dating back to at least 2018.