A federal judge in San Diego authorized the seizure of two domains, QScan and QTRouter, that the DOJ says were used by Chinese state-sponsored hacking group QTFY to scan for vulnerable devices and infiltrate U.S. critical infrastructure since at least 2018. Targets allegedly included NASA, the Federal Reserve, the Department of Energy, the DOJ and the Senate, according to an FBI affidavit.
Officials say QTFY, tied to a Nanjing-based network technology company, sold its infiltration platforms as services to clients including the Chinese military and Ministry of State Security, using infected devices as bots to obscure the origin of attacks. Attorney General Todd Blanche and FBI Director Kash Patel both framed the seizure as proof of an aggressive, ongoing campaign against Chinese hacking operations.
The DOJ described this as one of a series of similar technical operations in recent years, though the underlying affidavit indicates the platforms had already been operating undetected for roughly seven years.
The full dispatch is available from the source below.