started · updated
U.S. authorities seize domains used by Chinese-linked QTFY hacking platform
U.S. federal authorities, including the Department of Justice and the FBI, have seized core infrastructure used by a Chinese-linked cyber platform known as QTFY. The operation targeted domains associated with QScan and QTRouter, which investigators say were used to facilitate espionage and attacks against U.S. critical infrastructure and government agencies.
Targets identified in court filings include NASA, the Federal Reserve, the U.S. Senate, and the Departments of Energy, Justice, and Health and Human Services. The platform reportedly utilized thousands of infected internet-of-things devices to create an obfuscation network. Investigations suggest the group operated through Nanjing Xinjiuwei Network Technology Co., providing services to Chinese military and intelligence arms.
While initial reports suggested several agencies had been breached, U.S. officials later clarified that these organizations were targets of the QTFY platform.
In a separate but related cybersecurity development, international law enforcement and the FBI have also worked to dismantle the Sality malware botnet. This long-standing, decentralized peer-to-peer network has been active for over two decades, facilitating cryptocurrency theft and various cyberattacks globally.
Entities
FBI · Federal Reserve · NASA · Nanjing Xinjiuwei Network Technology Co · QTFY · U.S. Department of Justice
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The hacking platforms infected thousands of devices globally to create an obfuscation network. nationalcybersecurity.com · www.constructiondive.com
- [● 2 SOURCES] The QTFY platform targeted several U.S. government entities, including NASA, the Federal Reserve, and the U.S. Senate. nationalcybersecurity.com · www.constructiondive.com
- [○ 1 SOURCE] U.S. officials clarified that certain government agencies were targets of the QTFY platform rather than confirmed victims of a breach. cybernoz.com
- [● 2 SOURCES] The QTFY group operated through Nanjing Xinjiuwei Network Technology Co. to serve Chinese intelligence and military arms. nationalcybersecurity.com · www.constructiondive.com
- [● 2 SOURCES] Federal authorities seized domains used by the Chinese-linked cyber platform QTFY. nationalcybersecurity.com · www.constructiondive.com