Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 59 sources · 1 days · First seen · Last updated
Chinese state-sponsored cyber-espionage operation
Overview
U.S. authorities, including the FBI and the Department of Justice, have moved to dismantle a long-running Chinese state-sponsored cyber-espionage operation. The group, identified as ‘QTFY’, has been compromising critical infrastructure and government entities since at least 2018.
Investigations revealed that the group utilized two primary hacking platforms, QScan and QTRouter, to target sensitive agencies such as NASA, the U.S. Senate, the Federal Reserve, the Department of Energy, and the Department of Health and Human Services. The operation also extended to hospitals, telecommunications providers, and power companies.
Technical analysis indicates that QScan was used to infect thousands of internet-connected IoT devices globally, which were then integrated into the QTRouter network to obfuscate the origin of attacks. The infrastructure has been linked to the China-based Nanjing Xinjiuwei Network Technology Company, which allegedly provided services to China’s Ministry of State Security and the People’s Liberation Army. As part of the disruption efforts, prosecutors have successfully seized internet domains associated with the firm.
Entities
Department of Justice · Federal Bureau of Investigation · Nanjing Xinjiuwei Network Technology Company · NASA · QTFY
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] A Chinese government-backed hacking group has targeted hundreds of entities in the United States for years. thepulseofnh.com · weisradio.com
- [● 2 SOURCES] The hacking group, known as “QTFY”, includes former members of the Chinese military. thepulseofnh.com · weisradio.com
- [● 2 SOURCES] The group has compromised critical infrastructure since 2018. thepulseofnh.com · weisradio.com
- [● 2 SOURCES] Targeted entities include NASA, the NIH, HHS, the Department of Energy, the U.S. Senate, and the Federal Reserve. thepulseofnh.com · weisradio.com
- [● 2 SOURCES] In September 2024, the group conducted computer intrusions at three Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer. thepulseofnh.com · weisradio.com
- [● 2 SOURCES] Prosecutors seized three internet domains linked to the Chinese company Nanjing Xinjiuwei Network Technology Company. thepulseofnh.com · weisradio.com
Timeline
-
about 5 hours ago
[TECHNOLOGY] 2 sourcesFBI: Chinese hacking group targeted U.S. agencies for yearsThe FBI and DOJ report that a Chinese-backed hacking group, “QTFY,” has targeted hundreds of U.S. government agencies and critical infrastructure entities since 2018.
-
about 13 hours ago
U.S. authorities dismantle Chinese hacking platforms targeting NASA and SenateThe U.S. DOJ and FBI have dismantled a Chinese state-sponsored hacking operation that targeted NASA, the Federal Reserve, and the U.S. Senate using the QScan and QTRouter platforms.
Sources
24x7mag.com · abc17news.com · androidgeek.pt · bhaskarlive.in · cbs58.com · communitynews.com.au · criptotendencia.com · cryptobriefing.com · cryptonomist.ch · cybernoz.com · diebewertung.de · dpti.sa.gov.au · extra.ec · fnn.jp · freerepublic.com · frontenet.com · index.hr · internewscast.com · it-boltwise.de · itnews.com.au · itpro.com · joemygod.com · keyt.com · kmir.com · krdo.com · kurir.rs · kvia.com · localnews8.com · lykavitos.gr · nationalcybersecurity.com · news.az · news.yam.md · news20.ro · newsfactsnetwork.com · newsx.com · noregs.no · ntd.com · nuevolaredo.tv · otvoreno.me · pelop.gr · radiocolosal.com · rbfirehose.com · Reporter.gr · reversemortgagedaily.com · scmp.com · securityaffairs.co · sofokleousin.gr · spacemoney.com.br