Justice Department and FBI Seize Platforms Used by China State-Sponsored Hackers
Major Cybersecurity Action 🚨
The Justice Department and FBI have announced significant court-authorized domain seizures aimed at disrupting malicious cyber activities. Today, they targeted two hacking platforms, QScan and QTRouter, which were utilized by state-sponsored hackers from China to compromise U.S. critical infrastructure.
What Happened? 🔍
These platforms, operated by a group known as QTFY, were created by the Nanjing Xinjiuwei Network Technology Company. They provided hacking services to various Chinese government entities, including the Ministry of State Security and the People’s Liberation Army.
- QScan scans and infects thousands of IoT devices globally.
- QTRouter serves as an obfuscation network, masking the origin of cyber intrusions.
The seizure of these domains has rendered both QScan and QTRouter inoperable, significantly hindering the operations of these malicious actors.
Who Were the Victims? 😟
Among the victims of QTFY’s cyber intrusions are:
- NASA
- Federal Reserve
- Department of Energy
- Department of Justice
- Department of Health and Human Services
- National Institutes of Health
- U.S. Senate
This operation is part of a broader effort to combat indiscriminate hacking activities by state-sponsored groups from China. Previous actions by the FBI have included the removal of malware from thousands of U.S. computers and the disruption of botnets used for cyber exploitation.
Stay Informed 📢
Today, the FBI and NSA also released a cybersecurity advisory detailing indicators of compromise related to QTFY’s activities, based on their analysis dating back to 2018. For more insights on QTFY’s tactics, techniques, and procedures, check out the findings from Lumen Technologies’ Black Lotus Labs.
For further details, you can read the complete article here.