❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Officials disrupt Chinese espionage operation that hit multiple federal agencies

26 August 2026 at 15:35

Federal authorities Wednesday revealed a multi-layered Chinese state-sponsored espionage operation that’s targeted and compromised U.S. critical infrastructure, including multiple federal agencies, since 2018. 

Officials seized domains and unsealed an affidavit detailing how a Chinese government-funded front company assembled a botnet and complementary systems that allowed attackers to intrude highly sensitive networks.

The FBI and Justice Department said the state-sponsored group, known as “QTFY,” has targeted and intruded the networks of the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, National Institutes of Health, and, unsuccessfully in March, the Senate. 

Financial institutions, defense contractors, utility companies, telecom providers and hospitals have also been targeted by the threat group, which includes former members of China’s military, according to court records. 

Officials said QTFY also attempted, but was unsuccessful, in gaining access to a U.S. election system in June. 

The long-running operation, which officials obstructed by seizing malicious infrastructure, provided an expansive set of services. QTFY’s full hacking suite allowed attackers to scan and exploit vulnerabilities, infect IoT devices for a botnet, and conceal or reroute traffic.

QTFY’s operation was comprehensive with features that provided continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives, said Ryan English, information security engineer at Lumen Technologies’ Black Lotus Labs, which aided the disruption efforts. 

Officials said they seized three domains, which cut off access to QScan and QTRouter, the group’s primary platforms. 

“Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to national security,” John A. Eisenberg, assistant attorney general for national security, said in a statement. “These court-authorized seizures deny People’s Republic of China-linked hackers access to tools they use to mount online attacks against our nation’s critical infrastructure.”

The FBI, National Security Agency and Cyber National Mission Force released a joint cybersecurity advisory with QTFY’s known indicators of compromise Wednesday. Officials also detailed the China-linked hacking group’s affiliations and collaborations with other state-sponsored groups.

QTFY targeted sensitive networks in the U.S. and globally by exploiting vulnerabilities in multiple vendors’ products, including Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP and BeyondTrust, officials said.

QScan, the reconnaissance and vulnerability scanning tool, included more than 200 proof-of-concept exploits, according to court records. 

“It was designed for large-scale deployment. On a single day in 2024 for example, QScan processed over two million scanning and exploit tasks,” a special agent for the FBI said in the affidavit.

The Chinese hacking collective exploited multiple Ivanti zero-day vulnerabilities in September 2024 to intrude the networks of three DOE national laboratories, NIH, an HHS agency and a U.S.-based security device manufacturer. Officials said the seized domains were all used in those attacks. 

The FBI has been investigating QTFY, which operated out of a private China-based front company, Nanjing Xinjiuwei Network Technology Company, since at least 2019. The group has been consistently active for more than eight years. 

“Discovery of these private companies building networks for China is becoming more frequent,” English said. “We’re starting to see that when they’re getting exposed, some of these have been in business a few years before they’re found.”

The takedown follows a series of technical operations aimed at dismantling China state-sponsored attackers’ infrastructure, including an operation in early 2025 that allowed officials to remove PlugX malware from thousands of U.S.-based computers.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said in a statement. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”

The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberScoop.

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

23 July 2026 at 13:33

A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday.

Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said. 

The exploit just requires a view — no clicks — and allows attackers to steal the previous 90 days’ worth of email, the account’s password, search history, the victim organization’s email directory, two-factor authentication tokens and other newly created passwords.

“The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” officials wrote in the advisory. 

“Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”

The state-sponsored espionage group, also known as Void Blizzard, has compromised governments and organizations in the defense, education, energy, law enforcement, media, finance, transportation and technology sectors. 

Laundry Bear’s year-long campaign involving the exploitation of CVE-2025-66376 showcases more technical capabilities, including a custom JavaScript payload it delivers to targeted victims via phishing emails. The threat group could also likely adapt the novel data exfiltration and aggregation capability, dubbed “beehive,” to exploit other vulnerabilities, officials warned.

The defect’s medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.

The Russian state-supported group, which has been active since at least 2024, is still actively exploiting Zimbra Collaboration Suite instances that remain unpatched, officials said.

Authorities shared Thursday indicators of compromise, mitigation steps and urged organizations to update their vulnerable software.

“This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations” by identifying organizations with public-facing infrastructure, officials wrote in the advisory.

Once a target is identified, Laundry Bear also likely compiles email addresses for users to target with the exploit via phishing emails. Officials did not identify specific victims or describe the volume of organizations already compromised.

The joint cybersecurity advisory was issued by the United States, Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden.

The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

❌
❌