mimile
Back to feed

FBI, DOJ Seize Chinese Hacker Infrastructure on US Soil

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

FBI, DOJ Seize Chinese Hacker Infrastructure on US Soil

The U.S. Department of Justice and FBI on Wednesday announced the seizure of websites used by Chinese state-sponsored hackers to target critical infrastructure and federal systems. The domains supported QScan, a scanning and exploit platform, and QTRouter, an obfuscation network operated by the hacking group QTFY. The group has compromised networks of government agencies, hospitals, telecoms, power companies, financial institutions, and defense contractors.

Key Facts

  • The seized domains supported QScan and QTRouter, operated by the hacking group QTFY.
  • QTFY is controlled by Nanjing Xinjiuwei Network Technology Company, which received payments from China's Ministry of State Security.
  • QScan completed over 2 million scanning and exploit tasks in a single day in 2024.
  • The group exploited CVE-2024-24919 in Check Point Quantum Gateway days after disclosure in May 2024, affecting over 300 U.S. organizations.
  • Victims include NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.

Seizure and Attribution

The U.S. Department of Justice and FBI announced the disruption of QScan and QTRouter on Wednesday. FBI Director Kash Patel stated the tools were used by PRC cyber actors to hide the origin of their attacks. The FBI believes QTFY is controlled by Nanjing Xinjiuwei Network Technology Company, a private contractor in Jiangsu province. The company took payments from China's Ministry of State Security, indicating it hacked on behalf of the government. Members of QTFY include retirees from the Chinese army who used connections to obtain offensive security contracts.

Tool Capabilities and Impact

QScan ran on leased servers outside China and processed tasks such as web scraping and penetration testing. The platform had over 200 Python-based proofs-of-concept and completed over 2 million scanning and exploit tasks in a single day in 2024. QTFY exploited CVE-2024-24919 in Check Point Quantum Gateway days after disclosure in May 2024. The exploit allowed access to files and theft of sensitive information from more than 300 U.S. organizations. QTFY and its customers used QTRouter to obfuscate their identities.

Victim Organizations and Tracking

The Department of Justice listed victims including NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. Lumen Black Lotus Labs researcher Damon Rouse said the group has been active since May 2018. Nanjing Xinjiuwei Network Technology Company counts China's Ministry of State Security and the People's Liberation Army among its customers. Lumen began collaborating with the FBI on QTFY about a year ago. The targeting was throughout the western world and beyond, especially academia.