More

    FBI Seizes Chinese Hacking Platforms Used to Target US Agencies


    Key Takeaways

    FBI Takes QScan and QTRouter Offline

    Federal authorities disabled two interconnected hacking platforms on Aug. 26 by seizing domains essential to their communication and authentication functions. The Justice Department announced that QScan and QTRouter targeted critical infrastructure and sensitive networks operated by NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

    Court records attribute the platforms to QTFY, a Chinese state-sponsored hacking group employed by Nanjing Xinjiuwei Network Technology Company. The FBI affidavit supporting the domain seizures alleges that QTFY sold hacking services to customers that included China’s Ministry of State Security and the People’s Liberation Army. Three seized domains were hard-coded into the platforms, allowing the operation to render both systems inoperable.

    The seizures disrupted infrastructure that allegedly helped hackers identify vulnerable systems and disguise their connections to targeted networks. Attorney General Todd Blanche said:

    “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

    QScan Found Targets as QTRouter Concealed Attacks

    The two platforms performed different functions within an integrated reconnaissance, exploitation, and traffic-obfuscation system. The joint FBI, National Security Agency, and Cyber National Mission Force cybersecurity advisory states that QScan contained more than 200 proof-of-concept exploits and processed over 2 million scanning and penetration-testing tasks on one day in 2024. A May 2024 campaign exfiltrated data from more than 300 organizations worldwide.

    QScan automatically compromised vulnerable internet-connected devices and added them to QTRouter, which combined hijacked devices with commercial proxy services and leased virtual private servers. Black Lotus Labs analyzed QTFY’s infrastructure and described the group as an infrastructure provider supporting Chinese cyber operations. Routing traffic through devices near victims made malicious communications appear to originate from legitimate local users.

    FBI Director Kash Patel said:

    “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. These tools were used by PRC cyber actors to hide the origin of their attacks.”

    Compromised routers and other internet-of-things devices have also supported financially motivated cybercrime outside state-sponsored operations. Authorities previously dismantled a proxy network containing 369,000 hacked devices across 163 countries. That network allowed criminals to disguise activity involving cryptocurrency account takeovers, bank fraud, ransomware, and other schemes while generating more than $5.7 million for its operators.

    Operation Extends Infrastructure Takedown Campaign

    The latest seizures follow several court-authorized operations targeting Chinese state-sponsored cyber infrastructure. In January 2025, the FBI said it removed PlugX surveillance malware from approximately 4,258 U.S. systems infected by Mustang Panda. Federal authorities also disabled a Flax Typhoon botnet in 2024 and disrupted a Volt Typhoon botnet in 2023.

    The federal approach to foreign cyber threats is also expanding beyond conventional court-authorized seizures and malware-removal operations. An Aug. 12 presidential memorandum ordered the creation of a federally supervised cyber disruption program allowing vetted U.S. companies to propose missions against foreign criminal networks, with officials given 60 days to establish eligibility standards, target-review procedures, and safeguards.

    Federal investigators have increasingly disrupted the accounts, servers, domains, and network connections that enable foreign cyber operations. During a separate initiative in May, technology companies joined a DOJ operation that interrupted more than 1.4 million scam-linked accounts. Participants also blocked malicious internet traffic, decommissioned hosting infrastructure, and helped freeze more than $3.8 million in cryptocurrency.

    Individual users face different risks from sophisticated groups targeting government agencies and critical infrastructure, although both may exploit malware and compromised devices. Common protections include updating software, avoiding suspicious downloads, and verifying websites before entering sensitive information. Phishing and fake websites can install malware or expose passwords, while outdated routers can provide attackers with infrastructure for concealing separate intrusions.



    Source link

    Latest stories

    You might also like...