FBI, NSA disrupt China-linked QTFY hacking network targeting US critical infrastructure

scanx
Reviewed by
Shraddha JScanX News Team
Key Highlights
  • FBI and NSA seized domains for QTFY platforms QScan and QTRouter
  • Group processed over 2 million scanning tasks in 2024
  • Attacks targeted NASA, Federal Reserve, DoE, and 300+ organizations
  • CrowdStrike reports 58% of state-backed tech attacks linked to China
  • QTFY provided services to China’s Ministry of State Security
powered bylight_fuzz_icon
49369505

*this image is generated using AI for illustrative purposes only.

The Federal Bureau of Investigation and National Security Agency disrupted a China-linked hacking operation targeting U.S. critical infrastructure. Authorities seized domains used by the QTFY platform, halting its ability to scan and exploit vulnerable devices.

Operation Details

The Justice Department and FBI announced the action Wednesday, seizing domains for QScan and QTRouter. The NSA, FBI, and Cyber National Mission Force issued a joint advisory on activity dating back to 2018. FBI Director Kash Patel stated the tools were used by PRC cyber actors to hide attack origins.

QTFY is linked to Nanjing Xinjiuwei Network Technology Company. Investigators say the group provided services to paying customers including China’s Ministry of State Security and the People’s Liberation Army. The QTRouter network utilized compromised IoT devices, commercial proxy services, and leased virtual private servers.

Targets and Scale

According to court documents, QTFY targeted U.S. government and critical infrastructure networks. Affected entities included:

  • NASA
  • The Federal Reserve
  • Department of Energy
  • Department of Health and Human Services
  • National Institutes of Health
  • U.S. Senate

The affidavit describes a 2019 NASA intrusion and 2024 attacks involving three Department of Energy laboratories. QScan processed more than 2 million scanning and exploitation tasks in 2024. Investigators reported that QTFY stole server configuration files and user-account data from more than 300 U.S. organizations.

What the Numbers Show

The scale of automated exploitation indicates a high-volume, industrialized approach to cyber espionage. With over 2 million scanning tasks processed in 2024 alone, the operation prioritized breadth over depth, casting a wide net to identify vulnerabilities across hundreds of organizations before executing targeted data theft.

Broader Threat Landscape

The operation comes amid growing concerns over China-linked cyber activity. CrowdStrike Holdings found that more than 58% of state-backed cyberattacks against technology companies came from China-linked actors seeking AI technology and intellectual property.

Separately, researchers at Israeli cybersecurity firm Dream reported an AI-assisted campaign against Taiwanese government systems in July. The operation compromised at least 85 accounts and extracted more than 2,500 personnel records, showing signs of links to China.

JPMorgan Chase & Co. CEO Jamie Dimon has backed efforts to improve cooperation between companies on cybersecurity and critical infrastructure risks as threats from advanced AI increase.

Technical Evasion Methods

According to a Wall Street Journal report, the operation used so-called "airport" networks in China to blend malicious traffic with normal internet activity. Rumaisa Habib, a Stanford University Ph.D. student, noted thousands of such networks operate in China and are advertised through Telegram.

Damon Rouse, an engineer with Lumen’s Black Lotus Labs, said the approach gave attackers "plausible deniability." Attorney General Todd Blanche stated state-sponsored hackers preying on America’s critical infrastructure will be stopped and prosecuted.

How will the disruption of the QTFY platform impact the valuation and stock performance of cybersecurity firms specializing in IoT security and critical infrastructure protection?

What specific regulatory changes or executive orders might the U.S. government introduce to mandate stricter cybersecurity standards for entities like NASA and the Federal Reserve following these breaches?

Could the seizure of QScan domains lead to retaliatory cyber operations from Chinese state-sponsored groups, and how prepared are U.S. defense contractors to handle an escalation in AI-assisted attacks?

like17
dislike