Menu

Chinese Hacking Operations Disrupted by U.S.

1 month ago 0

Chinese hackers backed by the state made moves against crucial U.S. infrastructure, but the Department of Justice intervened to halt the cyber threats. The team on ‘Special Report’ takes a closer look at this national security risk, while also reviewing President Trump’s 97% endorsement success rate in recent Republican primaries.

Hackers affiliated with China accessed sensitive data from over 300 institutions, including U.S. defense firms, financial bodies, and universities. They breached three Energy Department labs, the National Institutes of Health (NIH), and a Health and Human Services (HHS) agency, according to newly unsealed court documents. This operation was conducted before the FBI took their hacking systems offline.

The group identified as QTFY, operated through a China-based firm. The FBI reported that the firm provided hacking services to clients such as China’s Ministry of State Security and the People’s Liberation Army. Former PLA members employed by the company used military links to obtain contracts for cyber operations.

QTFY utilized extensive internet scanning along with a network of compromised routers and devices to obscure the source of their attacks. By rerouting their malicious activities through devices near their targets’ networks, these hackers made their operations difficult to trace. Federal agencies have confirmed this tactic.

On Wednesday, the Justice Department and the FBI confiscated three domains vital for QTFY’s main platforms: QScan, which searched for vulnerable systems, and QTRouter, which concealed the hackers’ identities. These actions severely impaired the platforms by blocking the domains essential for their communication.

The scale of the operation was substantial. An FBI affidavit revealed that QScan processed over 2 million scanning tasks in a single day in 2024. This platform contained over 200 proof-of-concept exploits, searching for weaknesses that hackers could abuse.

Aaron Shraberg from Flashpoint commented on how China’s cyber landscape integrates commercial cybersecurity with state-sponsored activities, aiding in the creation of scalable hacking services.

QTFY targeted several U.S. entities, including NASA, the Justice Department, and the Federal Reserve, along with power companies, hospitals, and telecommunications providers. Attempts to breach election infrastructure were also part of their operations.

Fox News reached out to the Chinese embassy for a response. The operations were not universally successful. In 2019, QTFY failed to penetrate NASA because the agency had already fixed the targeted vulnerability. Similarly, attempts to infiltrate Senate networks and hospital systems were unsuccessful.

However, some attacks did succeed. In May 2024, QTFY exploited a Check Point vulnerability to steal data from over 300 organizations, including U.S. and international entities. Later, they accessed three Department of Energy labs and other installations using flaws in Ivanti software, according to a government advisory.

Attorney General Todd Blanche announced the seizure of the platforms and stated that the U.S. would stop and prosecute hackers targeting its critical infrastructure. This effort is part of a broader campaign to dismantle Chinese government-linked hacking groups.

Previously, the FBI disrupted other significant threat actors. In 2023, they dismantled a botnet linked to Volt Typhoon, a China-associated group, and the following year, they disabled another botnet used by Flax Typhoon. Last year, the FBI removed PlugX surveillance malware from over 4,000 affected U.S. computers.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *