FBI, NSA disrupt China-linked hacking network targeting U.S. critical infrastructure
The FBI and NSA said they disrupted a China-linked hacking operation, seized domains used by QTFY platforms QScan and QTRouter, and issued a joint advisory on activity dating back to 2018.
The Federal Bureau of Investigation (FBI) and National Security Agency have disrupted a China-linked hacking operation that targeted U.S. critical infrastructure and sensitive networks.
The agencies announced the action Wednesday, with the Justice Department and FBI saying they seized domains used by QTFY platforms QScan and QTRouter.
The NSA, FBI and Cyber National Mission Force also issued a joint cybersecurity advisory on the group’s activity dating back to 2018. "Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," FBI Director Kash Patel said in the Justice Department release. "These tools were used by PRC cyber actors to hide the origin of their attacks.
Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down." How QTFY Hid Its Attacks QTFY is linked by U.S. authorities to China-based Nanjing Xinjiuwei Network Technology Company.
Investigators say the group used QScan to scan and exploit vulnerable internet-connected devices and QTRouter to conceal the origin of its attacks.
According to court documents, QTFY provided hacking services to paying customers including China’s Ministry of State Security and the People’s Liberation Army.
The QTRouter network included compromised IoT devices, commercial proxy services and leased virtual private servers.
The FBI affidavit says QTFY activity targeted U.S. government and critical infrastructure networks, including NASA, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the U.S.
Senate.
It also describes a 2019 NASA intrusion and 2024 attacks involving three Department of Energy laboratories.
QScan processed more than 2 million scanning and exploitation tasks in 2024, according to the affidavit.
Investigators also said QTFY exploited a vulnerability and stole server configuration files and user-account data from more than 300 U.S. organizations.
The FBI said the seized domains were important to the operation of QScan and QTRouter, and the DOJ said taking control of them made the platforms inoperable.
Read Also: Elon Musk's SPCX Now Accounts for 5% of Nvidia Revenue, Gene Munster Says: 'The Script Has Flipped' China-Linked Cyber Threats The latest operation comes amid growing U.S. concerns over China-linked cyber activity.
CrowdStrike Holdings (NASDAQ: CRWD ) previously found that more than 58% of state-backed cyberattacks against technology companies came from China-linked actors, with attackers seeking AI technology and intellectual property.
Separately, researchers at Israeli cybersecurity firm Dream reported an AI-assisted campaign against Taiwanese government systems in July that compromised at least 85 accounts and extracted more than 2,500 personnel records.
The researchers said the operation showed signs of links to China.
JPMorgan Chase & Co. (NYSE: JPM ) CEO Jamie Dimon has also backed efforts to improve cooperation between companies on cybersecurity and critical infrastructure risks as threats from cyberattacks and advanced AI increase.
QTFY Used Extra Hiding Methods The operation also used so-called "airport" networks in China to blend malicious traffic with normal internet activity, according to a Wall Street Journal report published Wednesday.
Rumaisa Habib, a Stanford University Ph.D. student who studies those networks, told the Wall Street Journal that thousands of such networks operate in China and are advertised through Telegram.
Damon Rouse, an engineer with Lumen’s Black Lotus Labs, told the Wall Street Journal that the approach made the attackers harder to identify by giving them "plausible deniability." "State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted," Attorney General Todd Blanche said in the Justice Department release. "We are here to ensure security for the American people and will use every tool we have to keep that promise." "Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to the national security," Assistant Attorney General for National Security John A.
Eisenberg said. "These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure." The DOJ said the QTFY disruption is part of a broader series of U.S. operations targeting China-sponsored hacking networks.
The FBI and NSA also released indicators of compromise to help organizations identify the group’s activity.
Disclaimer: This content was partially produced with the help of AI tools and was reviewed and published editors.
Read Also: Baby Boomers Social Security Benefits Could Be 265% of What They Paid In — Here's Why