Chinese State-Sponsored Hackers Breach US Agencies and Departments
US agencies and departments have been breached by Chinese state-sponsored hackers, according to a recent disclosure. The hackers used a massive botnet of compromised IoT devices to obscure the origin of their traffic.
The breach affected computers belonging to NASA, the Federal Reserve, the Senate, the Department of Justice, and more.
The US Office of Public Affairs revealed that the victims of 'computer intrusion' included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate.
The Chinese hackers created a platform that provides paid-for hacking services on behalf of its customers. The two services, QScan and QTRouter, detect and infect internet-connected devices to use as part of a proxy network that obscures the origins of internet traffic, allowing Chinese hackers to slip into networks without detection.
The Justice Department and FBI have disrupted the operation of the hacking group, named 'QTFY', which was hired by the Nanjing Xinjiuwei Network Technology Company. The disruption is part of a range of technical operations designed to disrupt the ability of the People's Republic of China to launch hacking activities on US government systems and critical infrastructure.