China-Backed Hacking Group Targets US Government Agencies for Years
A Chinese government-backed hacking group known as QTFY has been targeting US government agencies and critical infrastructure for years, according to the FBI. The group, which includes former members of China's military, has compromised networks at hundreds of entities in the US since 2018, including NASA, National Institutes of Health, the Department of Energy, and the Federal Reserve.
The Justice Department and FBI said that QTFY hackers have used their infrastructure to compromise critical infrastructure in networks spanning from government agencies, hospitals, telecommunications providers, power companies, and defense contractors. The group's activities were exposed after prosecutors successfully seized three internet domains affiliated with the Chinese company Nanjing Xinjiuwei Network Technology Company.
Prosecutors allege that QTFY hackers conducted computer intrusions at Energy Department laboratories, NIH, an HHS agency, and an unnamed US security device manufacturer in September 2024. They also attempted to hack NASA in 2019 but were unsuccessful. The court documents do not state the scale of the attacks against other government agencies or the group's level of success in infiltrating specific networks.