Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 25 sources · 2 days · First seen · Last updated
U.S. action against China-linked QTFY hacking platform
Overview
U.S. federal authorities, including the Department of Justice and the FBI, seized core infrastructure and domains used by QTFY, a cyber platform linked to the Chinese firm Nanjing Xinjiuwei Network Technology Co. Investigators stated the platform utilized thousands of infected internet-of-things devices to facilitate espionage and attacks against U.S. government agencies and critical infrastructure, including NASA, the Federal Reserve, and the U.S. Senate.
Following the initial seizure, the Department of Justice provided clarifications regarding the scope of the group’s activities. While various institutions were targeted, officials noted that not all attempts were successful; for example, NASA prevented a breach through software corrections. However, confirmed intrusions were identified at certain Department of Energy national laboratories and health divisions. The Chinese embassy has contested these allegations, claiming the U.S. is using cybersecurity concerns to discredit the nation.
Entities
U.S. Department of Justice · QTFY · FBI · Nanjing Xinjiuwei Network Technology Co. · CrowdStrike
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 11 SOURCES] The Sality botnet has been active and infecting computers since 2003. itnerd.blog · livecoins.com.br · www.nationaltechnology.co.uk · blockcast.it · cybernoz.com · +6 more
- [● 7 SOURCES] The EggJagger payload stole at least $150,000 in cryptocurrency by swapping wallet addresses. itnerd.blog · blockcast.it · bitcoinethereumnews.com · www.cryptobreaking.com · www.spacemoney.com.br · +2 more
- [● 6 SOURCES] Sality had distributed malicious payloads to more than 15,000 infected machines worldwide. itnerd.blog · www.nationaltechnology.co.uk · blockcast.it · www.spacemoney.com.br · www.cointribune.com · +1 more
- [● 4 SOURCES] The takedown was achieved by replacing trusted peers in the peer-to-peer network with sinkholes. itnerd.blog · www.nationaltechnology.co.uk · blockcast.it · cybernoz.com
- [○ 1 SOURCE] The Sality botnet takeover was the most complex operation the company has ever conducted. www.nationaltechnology.co.uk
- [○ 1 SOURCE] Hackers began focusing on cryptocurrency theft using the botnet around 2017. livecoins.com.br
Timeline
-
10 days ago
[TECHNOLOGY] 12 sourcesSality botnet dismantled in multinational cybercrime operationInternational authorities and CrowdStrike have dismantled the Sality botnet, a Russia-based P2P network active since 2003 that used EggJagger malware to steal cryptocurrency via clipboard hijacking.
-
12 days ago
[TECHNOLOGY] 14 sourcesU.S. authorities seize domains used by Chinese-linked QTFY hacking platformU.S. authorities have seized domains used by the Chinese-linked QTFY platform to target government agencies and critical infrastructure, including NASA and the Federal Reserve.
Sources
ad-hoc-news.de · bitcoinethereumnews.com · blockcast.it · cisecurity.org · cointelegraph.com · cointribune.com · constructiondive.com · cryptobreaking.com · cybernoz.com · itnerd.blog · japantimes.co.jp · kaaltv.com · kesq.com · kowchecking.com · livecoins.com.br · mycryptoparadise.com · nationaltechnology.co.uk · news.az · newsweek.ro · ruse24.bg · saferworld.org.uk · sapo.pt · spacemoney.com.br · thehackernews.com · vinnews.com