ZeroHour
The Recordpublished ()ingested

US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

highThreat actor exploited in the wildimportance 76
AI summary · glm-5.3-flash

DOJ takes down QScan and QTRouter Chinese obfuscation platforms used to breach Federal Reserve, DOE, DOJ, and Senate since 2018.

The DOJ and FBI seized domains hard-coded into QScan and QTRouter, platforms run by Nanjing Xinjiuwei Network Technology Company and used by China's Ministry of State Security and PLA. QScan automatically infected IoT devices worldwide which were absorbed into QTRouter, allowing attackers to disguise intrusions as originating from other countries or local sources. Victims included the Federal Reserve, Department of Energy, DOJ, US Senate, NASA, HHS, NIH, plus hospitals, telecoms, power companies, financial institutions, and defense contractors. The FBI investigated QTFY since 2018, tracing a 2019 NASA incident through Pulse Secure VPN exploitation.

  • Seized domains hard-coded into both platforms, inoperable now
  • QTFY operated in 130+ countries as hackers-for-hire model
  • 2019 NASA breach traced to Pulse Secure VPN exploit
  • Investigation prompted by this year's attack on US Senate
  • Follows prior PlugX, Volt Typhoon, Flax Typhoon takedowns
Full article574 words · extracted from therecord.media · click to collapse

Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday.

The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China’s Ministry of State Security and the People’s Liberation Army, the department said in an affidavit. The targeted agencies included the Federal Reserve, Department of Energy, the DOJ itself, the U.S. Senate and NASA. 

QScan was used by hackers to scan and automatically infect internet of things devices around the world, the DOJ said, while QTRouter served as an obfuscation network that allowed malicious actors to conceal the origin of their attacks by making it appear that actions came from any of the infected devices. 

The tools allegedly enabled Chinese actors to make it look like the cyberattacks were coming from other countries and in some cases made it seem like the incidents were caused by local attackers. 

The tools were used by a state-sponsored group known as “QTFY” that targeted U.S. critical infrastructure and other sensitive networks, the Justice Department said. The affidavit said other victims include the Department of Health and Human Services, the National Institutes of Health and multiple hospitals, telecommunications providers, power companies, financial institutions and defense contractors. 

FBI Assistant Director Brett Leatherman said that QTFY exploited devices in more than 130 countries and “operates within a complex network of hackers-for-hire and government clients in China. 

Nanjing Xinjiuwei “sells stolen data and hacking services to Chinese military and intelligence agencies,” he said. “Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet or a network of machines secretly controlled by the adversary.”

Investigators said they have been investigating QTFY’s infrastructure since 2018 and continued until an attack on the U.S. Senate, which occurred this year. The affidavit does not explain whether specific senators or committees were attacked and the DOJ did not respond to requests for comment.  

The FBI and DOJ said the takedown made both QScan and QTRouter inoperable because the seized domains were hard-coded into both platforms and used for essential tasks like communication and authentication. 

The FBI said QTFY also had unspecified customers outside of the Chinese government.

One of the first attacks investigated by the FBI was a 2019 incident at NASA. Hackers attempted to exploit a vulnerability in Pulse Secure VPN. Investigators traced the IP addresses used in the NASA attack back to locations and email addresses in China. 

The Justice Department and FBI have repeatedly targeted similar platforms used by state-backed hackers to obfuscate their cyberattacks on U.S. institutions. U.S. law enforcement previously obtained court orders that allowed government agents to go into devices and remove malware installed by hackers from both China and Russia

Last year, the FBI removed the PlugX surveillance malware from thousands of U.S. computers and disrupted multiple botnets in 2024 that were run by prolific Chinese government hacking operations known as Volt Typhoon and Flax Typhoon

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools