The U.S. government has seized three internet domains used by a China-linked hacking group to operate tools that targeted U.S. critical infrastructure and government networks, including NASA, the Federal Reserve, the Energy Department and the U.S. Senate, according to the Justice Department.
The Justice Department and FBI announced the court-authorized seizures Wednesday in the Southern District of California. The seized domains – qtproxy.xyz, qt-proxy.org and qt-team.com – were used to operate two connected hacking platforms known as QScan and QTRouter.
Court documents identify the group behind the platforms as QTFY, which allegedly operates from the China-based Nanjing Xinjiuwei Network Technology Company.
The Justice Department said the group provided hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army.
QScan was used to scan for vulnerabilities and infect internet-connected devices, such as home routers, security cameras and other “internet-of-things” devices. Those compromised devices could then be added to QTRouter, a network used to route attacks through other computers and conceal their origin.
The government said the seized domains were hard-coded into both platforms and were needed for communication and authentication. Their seizure made QScan and QTRouter inoperable.
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” FBI Director Kash Patel said. “These tools were used by PRC cyber actors to hide the origin of their attacks.”
According to the affidavit, QTFY infrastructure has been used since at least 2018 to target hospitals, telecommunications companies, power providers, financial institutions and defense contractors, in addition to government agencies.
In September 2024, the group allegedly compromised three Energy Department national laboratories, the National Institutes of Health, a Health and Human Services agency and a U.S. security-device manufacturer by exploiting a previously unknown vulnerability in Ivanti equipment.
The affidavit said QScan processed more than 2 million scanning and exploit tasks in a single day in 2024. Investigators also found evidence that the group exploited another vulnerability to steal server configuration files and user-account details from more than 300 U.S. organizations.
Click Here For The Original Source.
