Botnet takedown exposes Chinese contractor behind US agency hacks

The FBI seized QScan and QTRouter, Chinese hacking platforms behind intrusions into NASA, the Federal Reserve, and the Senate.

CSBadmin
2 Min Read

The FBI and the US Justice Department announced the disruption of two Chinese state-sponsored hacking platforms, QScan and QTRouter, used by a group called QTFY to break into American government networks and critical infrastructure.

Court documents tie QTFY to Nanjing Xinjiuwei, a private Chinese firm that counts the Ministry of State Security and the People’s Liberation Army among its customers. Researchers at Lumen Black Lotus Labs, who tracked the group for 18 months and worked with the FBI for about a year, say it has been active since at least May 2018.

Victims named by the Justice Department include NASA, the Federal Reserve, the Energy and Justice departments, Health and Human Services, the National Institutes of Health, and the US Senate. Lumen says the crew favored academic and research targets across the Western world.

QScan scans and automatically infects IoT devices worldwide, adding them to QTRouter, an obfuscation network built from compromised devices, commercial proxies, and leased virtual private servers. The network hides the origin of attacks so they appear to come from local computers.

A federal court authorized seizure of three domains hardcoded into both tools: qtproxy.xyz, qt-proxy.org, and qt-team.com. FBI Director Kash Patel called the action a disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to conceal their attacks.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.