August 27, 04:25
FBI and DOJ seize domains tied to Chinese hackers that hit Fed, NASA, Senate
FBI and DOJ Disrupt Chinese Cyber Group That Hit Fed, NASA, US Senate
Beincrypto
The FBI and Justice Department seized the domains behind QScan and QTRouter. The domains were linked to Chinese state-sponsored hackers. The hackers targeted NASA, the Federal Reserve, and the US Senate. The listed victims also included the Department of Energy, the Department of Justice, the Department of Health and Human Services, and the National Institutes of Health. Court documents identify the operators as QTFY. QTFY was employed by Nanjing Xinjiuwei Network Technology Company. Court filings say QTFY sold hacking services to China's Ministry of State Security. The filings also name the People's Liberation Army as a client. QScan searched the internet for Internet of Things devices. QScan automatically infected thousands of those devices. Each compromised device joined the QTRouter network. QTRouter combined the devices with commercial proxy services and leased virtual private servers. The network made Chinese intrusions appear to originate outside China. Investigators found the seized domains hard-coded into both tools for communication and authentication. Removing the domains made QScan and QTRouter inoperable. Attorney General Todd Blanche said federal law enforcement investigated and disabled the People's Republic of China's malicious software. The case is being handled by prosecutors in the Southern District of California. The FBI removed PlugX malware from more than 4,000 American computers in 2025. The FBI disabled the Flax Typhoon botnet in 2024. The FBI disrupted Volt Typhoon infrastructure in 2023. Taiwanese threat intelligence firm TeamT5 reported that Chinese state-linked groups had doubled their attack volume after assigning routine work to artificial intelligence models.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.