Menu

Chinese Hacking Operation Stymied by FBI

1 month ago 0

Chinese hacking operations focused on key U.S. infrastructure were thwarted by the Department of Justice, blocking cyber infiltration attempts. The group, known as QTFY, stole data from over 300 organizations including U.S. defense contractors, universities, and financial institutions. They breached three Energy Department laboratories, the NIH, and an HHS agency before the FBI intervened, according to unsealed court records.

QTFY operated through a Chinese company, allegedly selling hacking services to China’s Ministry of State Security and People’s Liberation Army. Former PLA members helped secure cyber operation contracts using military relationships, as stated in an FBI affidavit.

QTFY employed a network of compromised devices to disguise attack origins, blending malicious traffic with legitimate traffic. Federal officials noted this method made the attacks harder to trace.

The Justice Department seized three domains powering QTFY’s main platforms, QScan and QTRouter, crippling their communication and authentication capabilities.

QScan processed over 2 million scanning tasks in a single day in 2024, highlighting the platform’s massive scope.

QTFY targeted significant federal systems such as NASA, the Federal Reserve, and Senate systems along with defense contractors, power companies, and hospitals.

An FBI, NSA, and Cyber National Mission Force advisory detailed failed attempts, such as a 2019 attack on NASA thwarted by proactive patching.

Successful attacks included a May 2024 data theft from over 300 organizations after exploiting a Check Point vulnerability. The advisory revealed subsequent breaches using zero-day flaws targeting DOE labs, NIH, and other institutions.

Attorney General Todd Blanche emphasized the prosecution of state-sponsored attackers targeting America’s infrastructure. The takedown is part of ongoing FBI efforts to dismantle hacking infrastructure linked to Chinese government-backed groups.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *