US Authorities Shut Down China-Linked Hacking Platforms
US authorities have taken down key online systems linked to two hacking platforms allegedly used by China state-sponsored hackers. The Justice Department and FBI announced on August 26 that they seized internet domains connected to QScan and QTRouter, which were allegedly used by the group QTFY employed by Nanjing Xinjiuwei Network Technology Company.
QTFY targeted US critical infrastructure and other sensitive networks, including NASA, the Federal Reserve, the departments of Justice, Energy, and Health and Human Services, the National Institutes of Health, and the U.S. Senate.
The platforms were used to compromise thousands of internet-connected devices worldwide, which were then added to the QTRouter network. QTRouter was designed to hide the source of malicious activity, making it appear to come from outside China, sometimes from devices located near the targeted networks.
According to the Justice Department, QScan and QTRouter were used to target hospitals, telecommunications providers, power companies, financial institutions, defense contractors, as well as four unnamed companies in the U.S. and South Korea.