US Shuts Down China’s Cyber Attack Network Targeting Military & Critical Infrastructure
US officials dismantled a hacking platform linked to Chinese threat actors targeting military and critical infrastructure networks.
Introduction
US government officials disclosed the dismantling of a hacking platform and botnet linked to Chinese threat actors targeting military and critical infrastructure networks. The Justice Department confirmed the disruption of operations tied to a group known as QTFY, which has been conducting cyberattacks since 2018.
Details of the Disruption
Tools Used
The action involved seizing domains associated with two key tools used by the group: QScan, a scanning and exploitation platform, and QTRouter, an obfuscation network. These tools were integral to the group’s ability to compromise internet-connected devices and mask malicious activities.
Impact of Seizures
The Justice Department stated that the seized domains were embedded in the malware code for both QScan and QTRouter, serving critical functions such as communication and authentication. The court-authorized seizures rendered the tools inoperable.
FBI Technical Advisory
Targeted Sectors
- Defense industrial base
- Local governments
- Telecommunications providers
- Higher education institutions
Vulnerabilities Exploited
- BeyondTrust
- CrushFTP
- Ivanti
- Check Point
- Atlassian
- Kentico
- F5
- Microsoft
- Citrix
- Fortinet
- Pulse Secure
Connections to Other Groups
The FBI noted that QTFY operates within the exploit development community and engages with freelance hacker networks and malicious cyber contracting marketplaces in the People’s Republic of China. The group has also maintained business ties with entities linked to the Salt Typhoon cyberespionage group and the i-Soon cyber intrusion firm.
Ongoing Threats
The disruption of QTFY’s infrastructure marks a significant operational setback for the threat actor, though the FBI emphasized that the group’s activities remain a persistent risk. The agency reiterated its warning about the ongoing threat posed by state-sponsored hacking campaigns targeting critical systems.
