ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

highThreat actor exploited in the wildimportance 70CVE-2019-11510
AI summary · glm-5.3-flash

DoJ corrected its statement to say US federal agencies were targets, not confirmed victims, of China-linked group QTFY's intrusions.

The US Department of Justice revised its press release to list NASA, the Federal Reserve, Department of Energy, DoJ, HHS, NIH and the US Senate as 'among the targets' of QTFY (aka QT AND QTCYBER), rather than victims. QTFY, active since 2018 and linked to Nanjing Xinjiuwei Network Technology Co with payments suggesting MSS sponsorship, operates the QScan vulnerability scanning platform and QTRouter obfuscation network, which underpin the Fast Labyrinth encrypted ORB relay network built from infected IoT devices and leased VPSs. The FBI seized qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com, disrupting QScan and QTRouter, while Lumen Black Lotus Labs reported the actor industrialized ORB networks for China-linked espionage. A 2019 NASA intrusion attempt exploited CVE-2019-11510, a critical Pulse Secure VPN flaw.

  • DoJ rewording suggests agencies were targeted, not necessarily compromised
  • QTFY operates QScan scanning and QTRouter obfuscation as a 'technical quartermaster'
  • FBI seized QTFY proxy domains, neutralizing Fast Labyrinth ORB infrastructure
  • Black Lotus Labs says QTFY industrialized ORB networks using IoT botnet nodes and VPSs
  • 2019 NASA intrusion attempt used CVE-2019-11510 in Pulse Secure VPN

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
Full article564 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 31, 2026Cyber Espionage / IoT Botnet

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.

Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were some of the victims of "computer intrusion activity" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China (PRC).

In the newly updated statement, the aforementioned agencies have been listed as "among the targets of QTFY." The update was reported by Reuters over the weekend.

"Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures," the DoJ said in a note.

According to the affidavit, QTFY (aka QT AND QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, adding payments from the Ministry of State Security (MSS) suggest that the company conducts malicious cyber activities on behalf of Beijing.

The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors.

Described as a technical quartermaster, QTFY has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. Two of the core products in its arsenal are QScan, a vulnerability scanning and exploitation platform, and QTRouter, which is an obfuscation network.

In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN.

The change in wording is significant as it suggests that while the activity may have targeted a broad range of organizations, only some of them were actually compromised.

The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com), effectively neutralizing the malware's functions.

Lumen Black Lotus Labs has revealed that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, creating a decentralized botnet of infected IoT devices and leased VPSs that enables them to obscure the true origins of the malicious activity.

QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter.

The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws. The entire architecture underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity.

"By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets," the affidavit alleged.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html