US Tackles Chinese Hacking Tools Used Against Federal Agencies
The US Department of Justice has taken down two Chinese hacking tools used against federal agencies since 2018. The tools, known as QScan and QTRouter, were run by China-based Nanjing Xinjiuwei Network Technology Company and primarily used by China's Ministry of State Security and the People's Liberation Army.
QScan was used to scan and infect internet of things devices worldwide, while QTRouter served as an obfuscation network that concealed the origin of cyberattacks. The tools allegedly enabled Chinese actors to make it appear that attacks were coming from other countries or local attackers.
The tools were used by a state-sponsored group known as QTFY, which targeted US critical infrastructure and sensitive networks. Victims include the Federal Reserve, Department of Energy, DOJ itself, U.S. Senate, NASA, and multiple hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
FBI Assistant Director Brett Leatherman stated that QTFY exploited devices in over 130 countries and operates within a complex network of hackers-for-hire and government clients in China.