The U.S. Department of Justice and FBI announced Wednesday that they had seized several domains connected to platforms allegedly operated by China state-sponsored hackers. According to the government, multiple federal agencies experienced computer intrusion activity, including the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, NASA, and the U.S. Senate.
Officials attribute the intrusions to a state-sponsored group identified as QTFY. The government claims the group relied on two pieces of malware, QTRouter and QScan, to carry out its operations. The People’s Republic of China (PRC) Ministry of State Security was reportedly among QTFY’s paying customers.
How the Malware Worked
According to the U.S. government, QScan scans and automatically infects thousands of Internet of Things (IoT) devices worldwide. Those compromised devices are then folded into the QTRouter network. Officials describe the system as a botnet that also functions as an “obfuscation layer,” masking the origin of malicious traffic. The affidavit states that QTFY’s infrastructure has been used to compromise U.S. critical infrastructure since 2018.
The group is said to be employed by the Nanjing Xinjiuwei Network Technology Company. As part of the enforcement action, the Justice Department seized three domains: qtproxy.xyz, qt-proxy.org, and qt-team.com. Each now displays an official seizure notice.
Tracing the Operation
The investigation dates back to at least 2019, when the FBI examined a system intrusion at NASA tied to CVE-2019-11510, a vulnerability that was later patched. Investigators traced the activity to two Gmail accounts and a phone number carrying a +86 country code, the dialing code for the PRC.
The group allegedly rented infrastructure from commercial platforms, which triggered a series of abuse complaints sent to the associated email accounts by hosting provider Hostwinds. According to the FBI, the group obtained the three seized domains between 2022 and 2024, registering them through domain registrar Namecheap and paying via PayPal.
A Pattern of Alleged Chinese Activity
While the PRC routinely denies conducting hacking operations against the United States, Chinese officials reportedly acknowledged late last year that the government was behind a series of attacks on U.S. infrastructure. In 2024, 30-year-old wiretap systems deployed by the U.S. government within telecom and internet providers were reportedly compromised by Chinese attackers.
Source
Image: tomshardware.com