The US government announced on Wednesday that it has disrupted a hacking platform and botnet used by Chinese threat actors in attacks aimed at military and critical infrastructure systems.
According to the Justice Department, the disruption efforts targeted a state-sponsored group called QTFY, which has been operating from a company called Nanjing Xinjiuwei Network Technology.
QTFY has offered its hacking services to the Chinese government and others, enabling attacks against many critical systems in the United States since its establishment in 2018.
Disruption of QTFY hacking platform
The US government has targeted two hacking services offered by QTFY: the scanning and exploitation platform QScan, and the obfuscation network QTRouter.
QScan is designed to scan the internet for vulnerable IoT devices and ensnare them in the QTRouter botnet, enabling threat actors to abuse the compromised devices to conceal their malicious activities and evade detection.
US authorities identified and seized domains used by QScan and QTRouter.
“Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” explained the Justice Department.
QTFY attacks and exploitation
A technical cybersecurity advisory published on Wednesday by the FBI reveals that QTFY has been developing malicious tools, trading malware and exploits, and maintaining botnets to carry out its attacks.
Targeted sectors include the defense industrial base, local government, telecoms, and higher education.
The agency said some of the group’s attempts to hack sensitive networks were unsuccessful, including attacks aimed at the Department of Energy, election systems, the Department of Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company.
Other attacks appear to have been successful at least to some extent, including against NASA, the Justice Department, the Federal Reserve, the Department of Energy, state governments, a major retailer, a telecoms company, defense contractors, universities, and financial institutions.
The hackers have been observed exploiting vulnerabilities in products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure.
“QTFY actors are active in the exploit development community, freelance PRC [People’s Republic of China] hacker networks, and PRC malicious cyber contracting and subcontracting marketplaces,” the FBI noted. “QTFY participates in the offensive end of network attack and defense events against Chinese critical infrastructure.”
The FBI also pointed out that the company behind QTFY has had business relationships with various entities connected to the Salt Typhoon cyberespionage group, the i-Soon cyber intrusion firm, and several others.
Related: Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown
Related: GlassWorm Botnet Disrupted
Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested
