Korean financial group among targets of China-linked hacking network | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


3D printed models of people working on computers and padlock are seen in front of displayed data leaking words and binary code in this picture illustration created on Feb. 1, 2022.

A Korean financial group was among the targets of a Chinese state-sponsored hacking network that the U.S. Department of Justice said it had disabled Wednesday.

The department and the Federal Bureau of Investigation (FBI) seized three domains behind two hacking platforms known as QScan and QTRouter, under court orders unsealed in the Southern District of California. The domains were written into the malware itself and handled basic functions such as communication and authentication, so the seizures left both platforms inoperable.

Court documents identify the operator as a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company. QTFY sold hacking services to paying customers that included China’s Ministry of State Security and the People’s Liberation Army, and its members include former officers of the Chinese military.

The two platforms worked together. QScan scanned the internet for vulnerable internet-connected devices such as home routers and security cameras, infected thousands of them and fed them into QTRouter. QTRouter then routed attack traffic through those devices, along with commercial proxies and leased servers, so intrusions appeared to come from outside China and sometimes from machines close to the target network.

The infrastructure has been used against critical infrastructure and sensitive networks worldwide since at least 2018, according to the FBI affidavit. On a single day in 2024, QScan handled more than two million scanning and exploit tasks. The FBI said devices and organizations in more than 130 countries were drawn into the network.

The Justice Department listed NASA, the Federal Reserve, the Senate, the National Institutes of Health and the Departments of Energy, Justice and Health and Human Services among the victims. Hospitals, power companies, telecommunications providers, financial institutions and defense contractors were also targeted, as were U.S. military-related networks.

The affidavit describes four companies it does not name: a financial group in Michigan, a medical center in Ohio, an insurance agency in Missouri and a Korean financial group.


A faceless hooded computer hacker in front of a dark green background

The Korean firm detected scanning of its internet protocol addresses from QTFY-linked addresses in November 2019 and again in May 2020, and complained to Hostwinds, the U.S. hosting provider whose addresses the traffic came from. Hostwinds forwarded the complaints to an email account linked to QTFY.

The company described itself in those complaints as a “National Security Objective Facility – Class A,” said unauthorized access was strictly prohibited and warned that it would treat the attempts as an illegal attack on another country’s critical infrastructure.

Korea assigns that top grade to sites whose failure would seriously damage national security or daily life. The affidavit does not name the company or say whether the scanning led to a breach.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said U.S. Attorney General Todd Blanche. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”

The announcement lands about a month before Chinese President Xi Jinping is due at the White House on Sept. 24 for a summit with U.S. President Donald Trump.


U.S. President Donald Trump, left, shakes hands with Chinese President Xi Jinping as they hold a bilateral meeting at Gimhae International Airport, on the sidelines of the APEC summit, in Busan on Oct. 30, 2025.

“This is something that we have talked about with our counterparts in China for many, many years,” Blanche said on Fox News, when asked whether Trump would raise the hacking at the summit. “And we know that it’s happening. And they know that we know that it’s happening. And it has to stop.”

China has consistently denied U.S. allegations of state-linked hacking. A Chinese Embassy spokesperson in Washington said Beijing was not familiar with the specifics of the Justice Department’s statement.

“The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law,” the spokesperson said, adding that the United States uses cybersecurity issues to smear or discredit China.

BY HYEON YE-SEUL [cho.yongjun1@joongang.co.kr]

This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.



Click Here For The Original Source.

——————————————————–

..........

.

.