Menu

Chinese Hacking Operations Target U.S. Infrastructure

1 hour ago 0

Chinese state-linked hackers recently targeted crucial U.S. infrastructure, including defense contractors, financial institutions, and universities. These activities were stopped when the Department of Justice intervened to block the cyber infiltration. Newly unsealed court records revealed that the group, known as QTFY, breached three Energy Department laboratories, the National Institutes of Health, and an HHS agency before the FBI disrupted their hacking platforms.

The QTFY Hacking Group

QTFY operated through a China-based company selling hacking services to entities such as China’s Ministry of State Security and the People’s Liberation Army. Some former PLA members were employed by the company, leveraging military contacts to secure contracts for offensive cyber operations. The group’s tactics included mass internet scanning and using compromised routers and cameras to obfuscate their attack sources.

Impact of the Justice Department’s Actions

The Justice Department and FBI took down three key domains of QTFY, dismantling their main platforms, QScan and QTRouter. QScan performed over 2 million scanning and penetration-testing tasks in a single day. The platform held more than 200 exploits and searched for vulnerabilities that hackers could take advantage of.

Aaron Shraberg from Flashpoint highlighted how China’s cyber capabilities have turned commercial cybersecurity techniques into state-sponsored operations. QTFY targeted American entities such as NASA, the Federal Reserve, and defense contractors.

Details of the Cyber Attacks

The FBI affidavit details how QTFY attempted to access NASA through a vulnerability in its virtual private network in 2019. This attempt failed due to a patched flaw. However, other intrusions were successful. In May 2024, QTFY exploited a Check Point vulnerability affecting power and telecommunications companies, compromising over 300 organizations.

Four months later, the hackers breached Ivanti Cloud Services Appliance software, gaining access to three Department of Energy laboratories and other significant institutions. The advisory did not specify the stolen information or duration of network access, nor if it disrupted operations.

Efforts to Curb Chinese Hacking

Attorney General Todd Blanche condemned these attacks on U.S. infrastructure, emphasizing efforts to stop and prosecute state-sponsored hackers. The FBI’s recent activities are part of broader efforts to dismantle infrastructures used by Chinese hacking groups. Previous operations dismantled botnets operated by groups like Volt Typhoon and removed malware such as PlugX from thousands of U.S. computers.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *