The US Department of Justice and the Federal Bureau of Investigation (FBI) announced on Wednesday (August 26) that two Chinese Communist Party (CCP) hacker platforms’ related domains have been seized under court authorization. This operation is the latest example of the US government’s recent strong efforts to combat a series of technical actions taken by CCP-supported hacker organizations in order to prevent malicious cyber actors from attacking critical infrastructure in the United States.
According to court documents unsealed by the US Southern District of California federal court, a CCP-supported hacker organization known as “QTFY” was employed by Nanjing Xinjiuwei Network Technology Company in China, responsible for establishing and operating two hacker platforms named “QScan” and “QTRouter”.
After the domains were seized under court authorization, these two hacker platforms have been rendered inoperable.
Court documents reveal that the CCP-supported hacker organization QTFY had breached systems of the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.
It is reported that the two hacker platforms, “QScan” and “QTRouter,” worked together in coordination. QScan scans a vast number of Internet of Things (IoT) devices globally and automatically infects them. The infected devices are then brought into the QTRouter network.
QTRouter then acts as an Obfuscation Network, disguising the source of attacks for QTFY. This means it can help QTFY hide the origin of attacks, making it appear as if the attacks are coming from a computer device infected in another country or even within close proximity to the target, rather than from within China.
US Attorney General Todd Blanche stated in a Justice Department release, “Malicious hackers supported by a foreign state targeting US critical infrastructure will be stopped and held accountable by the law. We are committed to ensuring the safety of the American people and will utilize all means to fulfill this pledge.”
Blanche emphasized that this operation is the latest in a series of recent technical actions aimed at dismantling indiscriminate hacker attacks supported by the CCP government.
FBI Director Kash Patel mentioned that CCP-supported hackers use these tools to target and attack US critical infrastructure while masking the true source of the attacks. He stressed that the FBI is intensifying efforts to combat cybercrimes and defend the United States’ homeland. He also expressed gratitude to all law enforcement agencies involved in this operation.
Furthermore, on the same day, Wednesday, the FBI and the National Security Agency (NSA) jointly released a cybersecurity report. According to the analysis of QTFY’s malicious cyber activities, the activities of this hacker organization can be traced back to at least 2018.
