SpaceX Launching NASA's Roman Space Telescope to Explore Dark Energy and Habitable Planets
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Federal authorities Wednesday revealed a multi-layered Chinese state-sponsored espionage operation thatβs targeted and compromised U.S. critical infrastructure, including multiple federal agencies, since 2018.Β
Officials seized domains and unsealed an affidavit detailing how a Chinese government-funded front company assembled a botnet and complementary systems that allowed attackers to intrude highly sensitive networks.
The FBI and Justice Department said the state-sponsored group, known as βQTFY,β has targeted and intruded the networks of the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, National Institutes of Health, and, unsuccessfully in March, the Senate.Β
Financial institutions, defense contractors, utility companies, telecom providers and hospitals have also been targeted by the threat group, which includes former members of Chinaβs military, according to court records.Β
Officials said QTFY also attempted, but was unsuccessful, in gaining access to a U.S. election system in June.Β
The long-running operation, which officials obstructed by seizing malicious infrastructure, provided an expansive set of services. QTFYβs full hacking suite allowed attackers to scan and exploit vulnerabilities, infect IoT devices for a botnet, and conceal or reroute traffic.
QTFYβs operation was comprehensive with features that provided continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives, said Ryan English, information security engineer at Lumen Technologiesβ Black Lotus Labs, which aided the disruption efforts.Β
Officials said they seized three domains, which cut off access to QScan and QTRouter, the groupβs primary platforms.Β
βTodayβs announcement demonstrates the Justice Departmentβs steadfast commitment to going on the offensive against cyber threats to national security,β John A. Eisenberg, assistant attorney general for national security, said in a statement. βThese court-authorized seizures deny Peopleβs Republic of China-linked hackers access to tools they use to mount online attacks against our nationβs critical infrastructure.β
The FBI, National Security Agency and Cyber National Mission Force released a joint cybersecurity advisory with QTFYβs known indicators of compromise Wednesday. Officials also detailed the China-linked hacking groupβs affiliations and collaborations with other state-sponsored groups.
QTFY targeted sensitive networks in the U.S. and globally by exploiting vulnerabilities in multiple vendorsβ products, including Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP and BeyondTrust, officials said.
QScan, the reconnaissance and vulnerability scanning tool, included more than 200 proof-of-concept exploits, according to court records.Β
βIt was designed for large-scale deployment. On a single day in 2024 for example, QScan processed over two million scanning and exploit tasks,β a special agent for the FBI said in the affidavit.
The Chinese hacking collective exploited multiple Ivanti zero-day vulnerabilities in September 2024 to intrude the networks of three DOE national laboratories, NIH, an HHS agency and a U.S.-based security device manufacturer. Officials said the seized domains were all used in those attacks.Β
The FBI has been investigating QTFY, which operated out of a private China-based front company, Nanjing Xinjiuwei Network Technology Company, since at least 2019. The group has been consistently active for more than eight years.Β
βDiscovery of these private companies building networks for China is becoming more frequent,β English said. βWeβre starting to see that when theyβre getting exposed, some of these have been in business a few years before theyβre found.β
The takedown follows a series of technical operations aimed at dismantling China state-sponsored attackersβ infrastructure, including an operation in early 2025 that allowed officials to remove PlugX malware from thousands of U.S.-based computers.
βState-sponsored malicious hackers preying on Americaβs critical infrastructure will be stopped and prosecuted,β Attorney General Todd Blanche said in a statement. βWe are here to ensure security for the American people and will use every tool we have to keep that promise.β
The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberScoop.
Read more of this story at Slashdot.
Read more of this story at Slashdot.