The U.S. Department of Justice (DoJ) and the FBI announced the seizure of domains allegedly used by a Chinese state-sponsored hacking group known as QTFY. This action aims to disrupt the group's ability to coordinate cyberattacks against U.S. targets.
According to the DoJ, QTFY's computer intrusion activity affected multiple U.S. government agencies and critical infrastructure since 2018. Victims include the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health (NIH), and the U.S. Senate.
The group allegedly utilized two pieces of malware, QScan and QTRouter. QScan was used to scan and automatically infect thousands of Internet of Things (IoT) devices worldwide. These infected devices were then added to the QTRouter network, which functioned as a botnet and an obfuscation layer to mask the origin of malicious traffic, making attacks appear to originate from other countries or local sources.
The DoJ attributes the activity to QTFY, a group reportedly employed by Nanjing Xinjiuwei Network Technology Company. This company is said to have offered computer hacking services to customers, including China's Ministry of State Security (MSS) and the People's Liberation Army (PLA).
Security researchers at Lumen Black Lotus Labs had been tracking QTFY's activity since May 2018 and collaborated with the FBI on the investigation for approximately a year prior to the domain seizures.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The FBI seized domains associated with QTFY, a China-backed botnet, to disrupt its operations. This action prevents the botnet, allegedly used by Chinese government hackers to target US federal agencies and defense contractors, from coordinating further cyberattacks.
The U.S. Department of Justice announced the disruption of QScan and QTRouter, two hacking platforms used by the Chinese state-sponsored group QTFY to target critical infrastructure and sensitive networks in the U.S. This action aims to dismantle the tools used by Chinese cyber actors to conceal their attack origins and compromise U.S. government agencies and research institutions.
The US Department of Justice announced the takedown of "QScan" and "QTRouter," hacking tools allegedly used by Chinese government actors to breach multiple federal agencies since 2018. These tools allowed attackers to scan and infect IoT devices globally, and to obfuscate the origin of cyberattacks, making them appear to come from other countries or local sources.
The U.S. Department of Justice and FBI seized three domains allegedly used by a Chinese state-sponsored hacking group, QTFY, to infiltrate systems at multiple U.S. government entities, including NASA, the Senate, and the Federal Reserve. This action disrupts an operation that has compromised U.S. critical infrastructure since 2018 using QTRouter and QScan malware.