< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 127 sources · 3 days · First seen · Last updated

US-China cyber espionage disruption

Overview

U.S. authorities, including the Department of Justice and the FBI, announced the disruption of a major cyber espionage operation linked to the Chinese-based QTFY hacking group. The group allegedly utilized platforms such as QScan and QTRouter to scan for vulnerabilities and obfuscate attack origins, providing services to entities including the People’s Liberation Army and China’s Ministry of State Security.

Initial reports indicated that several high-profile U.S. federal agencies were victims of the campaign. However, the Department of Justice later issued a clarification regarding the scope of the breaches. While the U.S. Senate, the Federal Reserve, and NASA were identified as targets, the revised statement noted that not all were successfully breached; for instance, an attempted intrusion into NASA was blocked by a software update.

Confirmed successful intrusions include three Department of Energy national laboratories, the National Institutes of Health, an agency affiliated with the Department of Health and Human Services, and a U.S. security equipment manufacturer. Additionally, a joint cybersecurity advisory noted that the group stole data from defense contractors, financial institutions, and universities in May 2024. China has denied the allegations, describing them as “politically motivated and baseless.”

Entities

FBI · NASA · Federal Reserve · QTFY · Ministry of State Security

Timeline

  1. 14 days ago

    [TECHNOLOGY] 3 sources
    US Department of Justice clarifies scope of Chinese cyber campaign

    The US Department of Justice clarified that while Chinese hackers targeted the US Senate, Federal Reserve, and NASA, not all agencies were successfully breached in a long-running cyber espionage campaign.

  2. 17 days ago

    [TECHNOLOGY] 123 sources
    U.S. authorities disrupt Chinese-linked hacking group targeting federal agencies

    U.S. authorities have disrupted a Chinese-linked hacking operation using the QScan and QTRouter platforms to target NASA, the Federal Reserve, and the U.S. Senate since 2018.

Sources

24x7mag.com · abc17news.com · abyan-time.net · ad-hoc-news.de · aljazeera.com · amgreatness.com · androidgeek.pt · antaranews.com · asiainfonews.com · askanews.it · balla.com.cy · baocalitoday.com · baogialai.com.vn · baotintuc.vn · barefootlax.com · bhaskarlive.in · bitcoinethereumnews.com · brasilemfolhas.com.br · cbnlb.com · cbs58.com · cedarnews.net · centroamerica360.com · china.timesofnews.com · cnbcindonesia.com · communitynews.com.au · conexion23.com · connectedtoindia.com · contrapodernews.com · criptotendencia.com · cryptobriefing.com · cryptonomist.ch · cybernoz.com · deultimominuto.net · dialogos.com.cy · diebewertung.de · dpti.sa.gov.au · elfinanciero.com.mx · elorbe.com · espanol.radio.cz · extra.ec · firststateupdate.com · fnn.jp · foxnews.com · freerepublic.com · frontenet.com · govtechreview.com.au · hawaiitribune-herald.com · index.hr