US seizes domains in Chinese espionage operation targeting federal agencies since 2018
This digest was compiled by AI from multiple sources — links to the originals are below.

Federal authorities on Wednesday disrupted a Chinese state-sponsored espionage operation that compromised multiple US federal agencies and critical infrastructure since 2018. Officials seized three domains linked to the group QTFY, cutting off access to its primary hacking platforms. The operation targeted the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health.
Key Facts
- The FBI and Justice Department identified the state-sponsored group as QTFY, which includes former members of China's military.
- QTFY targeted and intruded networks of the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health.
- Officials seized three domains, cutting off access to QScan and QTRouter, the group's primary platforms.
- QTFY exploited vulnerabilities in products from Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP, and BeyondTrust.
- The FBI, National Security Agency, and Cyber National Mission Force released a joint cybersecurity advisory with QTFY's known indicators of compromise on Wednesday.
Operation Disruption
Federal authorities seized three domains that cut off access to QScan and QTRouter, the group's primary platforms. The FBI and Justice Department said the state-sponsored group, known as QTFY, has targeted and intruded the networks of multiple federal agencies since 2018. Officials said QTFY also attempted, but was unsuccessful, in gaining access to a U.S. election system in June. John A. Eisenberg, assistant attorney general for national security, said the court-authorized seizures deny People's Republic of China-linked hackers access to tools used to mount online attacks against the nation's critical infrastructure.
Targeted Entities
QTFY targeted the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health. Financial institutions, defense contractors, utility companies, telecom providers, and hospitals have also been targeted by the threat group. The group unsuccessfully attempted to access the Senate in March. QTFY exploited vulnerabilities in products from Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP, and BeyondTrust.
Technical Capabilities
QTFY's full hacking suite allowed attackers to scan and exploit vulnerabilities, infect IoT devices for a botnet, and conceal or reroute traffic. The operation provided continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives, according to Ryan English, information security engineer at Lumen Technologies' Black Lotus Labs. The FBI, National Security Agency, and Cyber National Mission Force released a joint cybersecurity advisory with QTFY's known indicators of compromise on Wednesday.
1 source
US seizes domains in Chinese espionage operation targeting federal agencies since 2018



