FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) recently made an announcement regarding the disruption of two hacking platforms, QScan and QTRouter, operated by Chinese threat actors to target critical infrastructure and sensitive networks in the United States.

This activity has been linked to a Chinese state-sponsored group known as QTFY, working for Nanjing Xinjiuwei Network Technology Company.

The DoJ revealed that entities such as NASA, the Federal Reserve, the Department of Energy, and other government departments were victims of this cyber intrusion activity.

Security researcher Damon Rouse from Lumen Black Lotus Labs, who has been monitoring this activity for over 18 months, shared insights into the operations of the digital quartermaster. Nanjing’s clientele includes China’s Ministry of State Security and the People’s Liberation Army.

The FBI Director Kash Patel emphasized the significance of disrupting this global botnet and hacking platform used by Chinese hackers to target critical infrastructure in the U.S.

The tools QScan and QTRouter play crucial roles in scanning and infecting IoT devices globally, as well as concealing the origins of cyber attacks.

QScan exploits vulnerable IoT devices to infiltrate victim networks, while QTRouter acts as an obfuscation network to hide the true source of malicious activities.

The FBI detailed the operation of QScan and QTRouter, highlighting their role in cyber attacks and network obfuscation.

The hacking group QTFY has been actively involved in cyber operations since 2018, targeting critical systems in the U.S. and engaging in freelance hacking networks.

Overall, the disruption of these hacking platforms sheds light on the industrialization of cyber operations in China and the challenges posed by state-sponsored actors in executing complex campaigns with anonymity and global reach.