FBI Disables China-Linked Hacking Network Targeting US Infrastructure

iconCryptoBriefing
Share
AI summary iconSummary
The FBI and DOJ have taken down QScan and QTRouter, hacking platforms linked to a China-backed group. The network upgrade allowed the group to execute over 2 million tasks in May 2024, breaching more than 300 US organizations. QTFY, tied to Nanjing Xinjiuwei, provided hacking-as-a-service to Chinese government entities. Targets included NASA and the US Senate. The operation, active since 2018, is part of a broader US effort to counter PRC-linked cyber threats. The move aligns with ongoing government crypto regulation and cybersecurity enforcement.

The FBI and Department of Justice pulled the plug on two hacking platforms linked to a Chinese state-sponsored group, seizing three internet domains that served as the backbone for what officials described as a sprawling cyber espionage operation targeting US government networks and critical infrastructure.

The platforms, known as QScan and QTRouter, were allegedly operated by a group called QTFY, which US authorities have tied to employees of Nanjing Xinjiuwei Network Technology Company. By taking control of the domains, authorities effectively rendered both platforms inoperable, since the malware relied on those domains for communication and authentication.

A hacking-as-a-service operation at industrial scale

The scope of the operation was not subtle. In a single day in May 2024, QScan executed over 2 million scanning and exploitation tasks, exploiting a vulnerability in Check Point software to compromise more than 300 US organizations in one sweep.

Advertisement

QTFY allegedly offered hacking-as-a-service to Chinese government entities, including the Ministry of State Security and the People’s Liberation Army. The group used compromised Internet of Things devices and commercial proxy networks to mask its activity, making detection significantly harder for defenders. Their target list includes NASA, the Federal Reserve, the US Senate, and numerous other critical organizations.

The QTFY group’s activities date back to at least 2018, meaning they operated for roughly eight years before this particular enforcement action.

Part of a broader crackdown

FBI Director Kash Patel framed the seizure as a critical disruption of a global botnet used by Chinese state-sponsored hackers.

This operation fits into a pattern of escalating US action against PRC-linked cyber threats. Previous operations dismantled the Flax Typhoon botnet and removed PlugX malware from over 4,000 US computers.

The Chinese Embassy and Nanjing Xinjiuwei Network Technology Company have not publicly responded to the allegations. Beijing has historically denied involvement in state-sponsored hacking, a position that has become increasingly difficult to maintain as US prosecutors pile up indictments and technical evidence linking specific companies and individuals to intrusion campaigns.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.