FBI, DOJ Seize Chinese Hacker Infrastructure on US Soil | #cybercrime | #infosec


Cyberwarfare / Nation-State Attacks
,
Fraud Management & Cybercrime

QScan and QTRouter Used US-Registered Domains and Overseas Servers to Mask Operations

Image: Shutterstock

The United States government took down websites that Chinese state hackers used to operate as hacking platforms for targeting critical infrastructure and federal systems, the Department of Justice and FBI announced Wednesday.

See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime

The seized domains supported a scanning and exploit platform named QScan and an obfuscation network called QTRouter, both run by a hacking group known as QTFY. It has intruded into the networks of numerous government agencies, hospitals, telecommunications providers, power companies, financial institutions and defense contractors, said an FBI investigator.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks.”

Authorities believe the hacking group is controlled by a private contractor from the Nanjing Xinjiuwei Network Technology Company, based in the eastern province of Jiangsu. It took payments from the Chinese Ministry of State Security, indicating it was a private contractor hacking on behalf of the government, an FBI affidavit states.

Members of the group include retirees from the Chinese army who used their connections to obtain offensive security contracts, the FBI said. They used QScan, QTRouter, as well as botnets of compromised internet of things devices, for their own operations while also selling access to those tools to other hacking groups.

“QTFY actors and their customers can use QScan to automatically scan and exploit thousands of vulnerable IoT devices worldwide, which QTFY actors can then add as botnet nodes in the QTRouter obfuscation network,” the FBI said.

QScan ran on leased servers outside of China and processed a large amount of tasks every day, such as web scraping and penetration testing. It had over 200 Python-based proofs-of-concept in its database and completed over 2 million scanning and exploit tasks in a single day in 2024.

The tool successfully exploited a vulnerability in Check Point Quantum Gateway, tracked as CVE-2024-24919, merely days after the flaw was disclosed in May 2024. The threat actor was able to access files on victim systems and steal sensitive information including server configuration files and user account details from more than 300 organizations in the U.S., the FBI said.

QTFY and its customers obfuscate their identities with QTRouter. “For example, by routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets,” the FBI said.

One of the domains seized in the DOJ and FBI’s operation managed compromised devices and knitted the obfuscation network.

In 2019, QTFY attempted to gain unauthorized access to a NASA server through a critical flaw in Pulse Secure Virtual Private Network, tracked as CVE-2019-11510. The vulnerability could allow attackers to steal legitimate users’ login credentials and grant them remote access to a protected network.

The intruder’s IP address was leased by an account registered to an individual in Changsha, China, who used a Gmail address that contained “qtfy” and a telephone number with China’s country code, the FBI found.

The email addresses associated with the suspect was linked to another trove of email accounts in 2020 and 2021 that showed the attackers leasing an arsenal of virtual private servers, IP addresses and domain names.

QTFY also targeted the Federal Reserve, the department of Energy, Justice, Health and Human Services, the Senate and private companies including a medical center in Ohio, a financial group in Michigan and an insurance agency in Missouri.

In the case of the Ohio medical center, the group leased virtual private servers from U.S.-based hosting company Hostwinds, which found the actors exploiting the center’s Pulse Secure VPN vulnerability and sent an abuse complaint in August 2020.

“Attacking healthcare in a pandemic is just wrong,” the medical center told Hostwinds, which relayed the message to the attackers.

Hostwinds had sent many complaints to QTFY via email in 2019 and 2020 whenever the attacker’s victims identified Hostwinds IP addresses during incident response and asked the virtual server provider to act, the FBI’s search warrant for the abuse complaints found.

In September 2024, the threat actor turned on three DOE National Laboratories, the National Institutes of Health and a U.S. security device manufacturer in a zero-day attack against Ivanti Cloud Services Appliances. It remotely accessed all six victim’s networks (seeL Ivanti Vulnerability Again Forces Emergency Patches).

The FBI affidavit calling for the domain seizures was sworn before a judge Monday, signaling a quick turnaround as the domains were locked down soon after.

The domains were registered through U.S. domain name registrars Namecheap and NameSilo.



Click Here For The Original Source.

——————————————————–

..........

.

.