QTFY hacked NASA, Federal Reserve, and U.S. Senate networks, DOJ says
The Justice Department and FBI on Wednesday announced the seizure of two hacking platforms used by a Chinese state-sponsored group to target U.S. critical infrastructure and other sensitive networks. The platforms — QScan and QTRouter — are now inoperable, Attorney General Todd Blanche said.
The two platforms work in tandem, according to the Justice Department press release. QScan scans and automatically infects thousands of internet-of-things devices worldwide, and the infected devices are added to the QTRouter network. QTRouter consists of the compromised IoT devices along with commercial proxy service devices and leased virtual private servers. It serves as an obfuscation network that allows QTFY and other malicious cyber actors to conceal the China-origin of their operations, because the malicious communications appear to come from computers outside of China — and sometimes from computers local to the targeted networks.
Because the domains were hard-coded into the QScan and QTRouter malware for essential tasks such as communication and authentication, the court-authorized seizures rendered both platforms inoperable, the Justice Department said.
The affidavit underlying the seizure describes a Chinese state-sponsored group the government identifies as QTFY, whose members are employed by the China-based firm Nanjing Xinjiuwei Network Technology Company. According to court documents, QTFY has hacked into the networks of NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
The same court documents say QTFY offers computer hacking services to paying customers including China’s army and Ministry of State Security; QScan and QTRouter are among those services, the Justice Department said.
Blanche, the attorney general, said in a statement: “Federal law enforcement investigated and disabled [China’s] malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
John A. Eisenberg, the Assistant Attorney General for National Security, said in a statement: “These court-authorized seizures deny [China]-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.”