Interestana
Home/News/FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data

The U.S. Department of Justice (DoJ) announced on Wednesday the successful disruption of two hacking platforms, QScan and QTRouter, which were utilized by Chinese threat actors to target critical infrastructure and other sensitive networks within the United States. These operations have been attributed to a Chinese state-sponsored group identified as QTFY. The DoJ stated that QTFY is employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), a China-based entity. The disruption was achieved through a coordinated effort involving the Federal Bureau of Investigation (FBI) and other international law enforcement partners. The FBI's investigation revealed that QTFY used these platforms to conduct extensive malicious cyber activities, including the exfiltration of sensitive data from numerous U.S. organizations. The platforms QScan and QTRouter were designed to facilitate unauthorized access to victim networks and to maintain persistent presence for data theft. QScan, specifically, was identified as a tool used for scanning and identifying vulnerable systems, while QTRouter served as a command-and-control infrastructure to manage compromised devices and direct malicious traffic. The DoJ emphasized that this action represents a significant blow to the cyber espionage capabilities of the Chinese state. The operation underscores the persistent threat posed by state-sponsored hacking groups to national security and economic stability. The FBI's investigation into QTFY's activities spanned several years, involving the analysis of vast amounts of digital evidence and collaboration with private sector cybersecurity firms. The disruption involved taking down the servers and infrastructure that hosted the QScan and QTRouter platforms, thereby rendering them inoperable. This action aims to prevent further data theft and protect critical U.S. networks from future attacks by this group. The DoJ also highlighted the importance of international cooperation in combating transnational cybercrime. The disruption of QTFY's infrastructure is part of a broader U.S. government strategy to hold malicious cyber actors accountable and to deter future malicious cyber activities. The investigation and subsequent disruption were executed under the authority of U.S. law, aiming to safeguard American interests and digital infrastructure. The FBI continues to monitor the activities of QTFY and other state-sponsored groups, and remains committed to protecting the United States from cyber threats. The specific types of data stolen by QTFY were not detailed in the announcement, but the targeting of critical infrastructure suggests potential for significant economic and national security impacts. The DoJ's announcement serves as a warning to organizations to strengthen their cybersecurity defenses against sophisticated state-sponsored threats.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next