Chinese state-backed hackers allegedly used two cyber platforms to target major US government institutions, including NASA, the Federal Reserve, the Justice Department and the US Senate, according to court documents unsealed Wednesday.
The Justice Department said the hackers also targeted the Energy Department, the Department of Health and Human Services and the National Institutes of Health. US authorities seized three internet domains connected to the QScan and QTRouter platforms, effectively shutting down the systems.
According to an FBI affidavit, the platforms were allegedly developed and operated by QTFY, a China-based group associated with Nanjing Xinjiuwei Network Technology Company. The company is accused of conducting cyber operations on behalf of the Chinese government and receiving funding from China’s Ministry of State Security.
QScan reportedly searched the internet for vulnerable devices and automatically infected thousands of computers and other systems. Those compromised devices were then incorporated into QTRouter, allowing hackers to hide the actual source of their attacks by routing malicious traffic through infected devices located near their targets.
The group allegedly targeted a wide range of organizations, including hospitals, telecommunications companies, energy providers, financial institutions and defense contractors.
The FBI began investigating QTFY after an attempted intrusion into NASA’s network in 2019. The attack was unsuccessful because NASA had already fixed the vulnerability targeted by the hackers.
US officials said the operation disrupted a global hacking network linked to Chinese state-sponsored activity. The FBI and National Security Agency also issued a cybersecurity advisory detailing QTFY activities dating back to at least 2018.
NEWS DESK
PRESS UPDATE
