US DoJ and FBI seize Chinese hacking platforms
The United States Justice Department has announced that it has disrupted a Chinese hacking operation responsible for recent break-ins and attempts on the US Justice Department, NASA, the Federal Reserve, the Senate and other sensitive government agencies.
Court-authorised domain seizures were used to deny malicious cyber actors access to two complementary hacking platforms known as QScan and QTRouter, used to target US critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” said Attorney General Todd Blanche. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division and DOJ partners, we seized adversary infrastructure and shut these platforms down.”
According to court documents, QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. These computer hacking services include QScan and QTRouter, which work in conjunction. QScan scans and automatically infects thousands of IoT devices, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an obfuscation network to allow QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorised seizures made QScan and QTRouter inoperable.
The Australian Signals Directorate (ASD) is yet to comment on the takedown as of the time of this article.
ASD warns of active exploitation of development platform in Australia
The Australian Signals Directorate has issued an alert with high status related to the TeamCity...
Darktrace completes IRAP assessments for key products
Darktrace has completed an IRAP assessment for Darktrace / NETWORK and Darktrace / OT, the...
Quest Software completes IRAP assessments
Quest Software has achieved IRAP certification for both its Quest Trusted Data Management...
