← All stories
● Covered by 4 sources · 4 reportsMedium impact4 neutral

US Seizes Domains Linked to Chinese Hacking Group QTFY Targeting Government Agencies

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • US Justice Department and FBI seized domains linked to QTFY.
  • QTFY is a Chinese state-sponsored hacking group.
  • Malware QTRouter and QScan were used in attacks.
  • Targets included NASA, Federal Reserve, and U.S. Senate.
  • Operations have been active since at least 2018.

Domain Seizures Disrupt Hacking Operations

The U.S. Department of Justice (DoJ) and the FBI announced the seizure of domains allegedly used by a Chinese state-sponsored hacking group known as QTFY. This action aims to disrupt the group's ability to coordinate cyberattacks against U.S. targets.

Targeted U.S. Government Entities

According to the DoJ, QTFY's computer intrusion activity affected multiple U.S. government agencies and critical infrastructure since 2018. Victims include the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health (NIH), and the U.S. Senate.

Malware and Botnet Infrastructure

The group allegedly utilized two pieces of malware, QScan and QTRouter. QScan was used to scan and automatically infect thousands of Internet of Things (IoT) devices worldwide. These infected devices were then added to the QTRouter network, which functioned as a botnet and an obfuscation layer to mask the origin of malicious traffic, making attacks appear to originate from other countries or local sources.

Attribution and Employment

The DoJ attributes the activity to QTFY, a group reportedly employed by Nanjing Xinjiuwei Network Technology Company. This company is said to have offered computer hacking services to customers, including China's Ministry of State Security (MSS) and the People's Liberation Army (PLA).

Ongoing Collaboration

Security researchers at Lumen Black Lotus Labs had been tracking QTFY's activity since May 2018 and collaborated with the FBI on the investigation for approximately a year prior to the domain seizures.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The FBI seized domains associated with QTFY, a China-backed botnet, to disrupt its operations. This action prevents the botnet, allegedly used by Chinese government hackers to target US federal agencies and defense contractors, from coordinating further cyberattacks.

The U.S. Department of Justice announced the disruption of QScan and QTRouter, two hacking platforms used by the Chinese state-sponsored group QTFY to target critical infrastructure and sensitive networks in the U.S. This action aims to dismantle the tools used by Chinese cyber actors to conceal their attack origins and compromise U.S. government agencies and research institutions.

The US Department of Justice announced the takedown of "QScan" and "QTRouter," hacking tools allegedly used by Chinese government actors to breach multiple federal agencies since 2018. These tools allowed attackers to scan and infect IoT devices globally, and to obfuscate the origin of cyberattacks, making them appear to come from other countries or local sources.

The U.S. Department of Justice and FBI seized three domains allegedly used by a Chinese state-sponsored hacking group, QTFY, to infiltrate systems at multiple U.S. government entities, including NASA, the Senate, and the Federal Reserve. This action disrupts an operation that has compromised U.S. critical infrastructure since 2018 using QTRouter and QScan malware.