top of page

News

Public·4 members

Jake Geier
Jake Geier

DOJ, FBI Seize Domains Powering Chinese State-Sponsored "QScan" and "QTRouter" Hacking Platforms


What:

  • DOJ and FBI executed court-authorized seizures of domains hard-coded into two hacking platforms, "QScan" and "QTRouter," disabling both tools since the domains were essential for their communication and authentication functions as described in court documents unsealed in the Southern District of California U.S. Department of Justice

  • The platforms were created and operated by a PRC state-sponsored group known as "QTFY," employed by China-based Nanjing Xinjiuwei Network Technology Company — this attribution comes directly from unsealed court documents, not inference U.S. Department of Justice

  • QTFY allegedly sold hacking services to customers including China's Ministry of State Security and the People's Liberation Army Bitcoin News

  • The two platforms performed different functions within an integrated reconnaissance, exploitation, and traffic-obfuscation system Bitcoin News

  • The FBI and NSA also issued a joint cybersecurity advisory detailing indicators of compromise tied to QTFY activity dating back to at least 2018 GBHackers


⚠️Impact:

  • Confirmed victims of QTFY intrusion activity include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate U.S. Department of Justice

  • The platforms were used to hide the origin of attacks on U.S. critical infrastructure and major federal agencies HousingWire

  • Loss of domain infrastructure disrupts QTFY's current operational capability, though it doesn't preclude the group standing up new infrastructure


💡Recommendations:

  • Review the joint FBI/NSA advisory's indicators of compromise against network logs, particularly for organizations in federal, energy, health, and research sectors

  • Treat this as a reminder to audit exposure from any historical or ongoing connections tied to Chinese state-sponsored infrastructure, given the 2018+ activity window

  • Watch for successor infrastructure — seizure disables current domains but not the underlying actor or tooling capability

Read the full story HERE

9 Views
bottom of page