Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Nation-State

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.

China - US cybersecurity

The US government announced on Wednesday that it has disrupted a hacking platform and botnet used by Chinese threat actors in attacks aimed at military and critical infrastructure systems.

According to the Justice Department, the disruption efforts targeted a state-sponsored group called QTFY, which has been operating from a company called Nanjing Xinjiuwei Network Technology.

QTFY has offered its hacking services to the Chinese government and others, enabling attacks against many critical systems in the United States since its establishment in 2018. 

Disruption of QTFY hacking platform

The US government has targeted two hacking services offered by QTFY: the scanning and exploitation platform QScan, and the obfuscation network QTRouter. 

QScan is designed to scan the internet for vulnerable IoT devices and ensnare them in the QTRouter botnet, enabling threat actors to abuse the compromised devices to conceal their malicious activities and evade detection.

US authorities identified and seized domains used by QScan and QTRouter.

Advertisement. Scroll to continue reading.

“Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” explained the Justice Department.

QTFY attacks and exploitation

A technical cybersecurity advisory published on Wednesday by the FBI reveals that QTFY has been developing malicious tools, trading malware and exploits, and maintaining botnets to carry out its attacks.

Targeted sectors include the defense industrial base, local government, telecoms, and higher education. 

The agency said some of the group’s attempts to hack sensitive networks were unsuccessful, including attacks aimed at the Department of Energy, election systems, the Department of Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company.

Other attacks appear to have been successful at least to some extent, including against NASA, the Justice Department, the Federal Reserve, the Department of Energy, state governments, a major retailer, a telecoms company, defense contractors, universities, and financial institutions. 

The hackers have been observed exploiting vulnerabilities in products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure. 

“QTFY actors are active in the exploit development community, freelance PRC [People’s Republic of China] hacker networks, and PRC malicious cyber contracting and subcontracting marketplaces,” the FBI noted. “QTFY participates in the offensive end of network attack and defense events against Chinese critical infrastructure.”

The FBI also pointed out that the company behind QTFY has had business relationships with various entities connected to the Salt Typhoon cyberespionage group, the i-Soon cyber intrusion firm, and several others.

Related: Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown

Related: GlassWorm Botnet Disrupted

Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.