FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.
The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.
‘Elon Musk’ Was a Prolific Money Launderer for Hackers and Drug Traffickers. It Was Secretly the FBI
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
FBI seized domains disabling QScan and QTRouter malware run by China-linked QTFY group behind intrusions at NASA, DOJ, Senate and other agencies.
The Justice Department and FBI seized domains hard-coded into two malware tools, QScan and QTRouter, operated by a Chinese state-sponsored group called QTFY, tied to a Nanjing-based company that sold hacking services to China's Ministry of State Security and the PLA. QScan infected IoT devices worldwide while QTRouter combined them with commercial proxies and rented servers to build an obfuscation network that masked attack origins. Victims include NASA, the Federal Reserve, the Departments of Energy and Justice, HHS, NIH, and the U.S. Senate. The FBI and NSA published a joint advisory with indicators of compromise, the latest in operations against Mustang Panda, Flax Typhoon, and Volt Typhoon infrastructure.