FBI shuts down sprawling China-linked hacking network that scanned millions of US targets

1 hour ago 8

The FBI and Department of Justice pulled the plug on two hacking platforms linked to a Chinese state-sponsored group, seizing three internet domains that served as the backbone for what officials described as a sprawling cyber espionage operation targeting US government networks and critical infrastructure.

The platforms, known as QScan and QTRouter, were allegedly operated by a group called QTFY, which US authorities have tied to employees of Nanjing Xinjiuwei Network Technology Company. By taking control of the domains, authorities effectively rendered both platforms inoperable, since the malware relied on those domains for communication and authentication.

A hacking-as-a-service operation at industrial scale

The scope of the operation was not subtle. In a single day in May 2024, QScan executed over 2 million scanning and exploitation tasks, exploiting a vulnerability in Check Point software to compromise more than 300 US organizations in one sweep.

QTFY allegedly offered hacking-as-a-service to Chinese government entities, including the Ministry of State Security and the People’s Liberation Army. The group used compromised Internet of Things devices and commercial proxy networks to mask its activity, making detection significantly harder for defenders. Their target list includes NASA, the Federal Reserve, the US Senate, and numerous other critical organizations.

The QTFY group’s activities date back to at least 2018, meaning they operated for roughly eight years before this particular enforcement action.

Part of a broader crackdown

FBI Director Kash Patel framed the seizure as a critical disruption of a global botnet used by Chinese state-sponsored hackers.

This operation fits into a pattern of escalating US action against PRC-linked cyber threats. Previous operations dismantled the Flax Typhoon botnet and removed PlugX malware from over 4,000 US computers.

The Chinese Embassy and Nanjing Xinjiuwei Network Technology Company have not publicly responded to the allegations. Beijing has historically denied involvement in state-sponsored hacking, a position that has become increasingly difficult to maintain as US prosecutors pile up indictments and technical evidence linking specific companies and individuals to intrusion campaigns.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article