US Authorities Shut Down China-Linked Hacking Platforms
The US Department of Justice (DOJ) and Federal Bureau of Investigation (FBI) have shut down two hacking platforms allegedly used by a China state-sponsored group to target US critical infrastructure and sensitive networks.
The DOJ announced that they seized internet domains connected to QScan and QTRouter, which were allegedly used by the group identified as QTFY, employed by Nanjing Xinjiuwei Network Technology Company in China.
The targets of these hacking attempts included NASA, the Federal Reserve, the departments of Justice, Energy, and Health and Human Services, the National Institutes of Health, and the US Senate. The alleged hackers also targeted hospitals, telecommunications providers, power companies, financial institutions, defense contractors, and four unnamed companies in the US and South Korea.
The QScan platform searched for and infected thousands of internet-connected devices worldwide, which were then added to the QTRouter network. QTRouter was designed to hide the source of malicious activity, making it appear as if it came from outside China, sometimes from devices located near the targeted networks.