US intervenes domains of a Chinese group accused of cyberattacks on NASA, the Fed, and the Senate

US seizes domains of a Chinese group accused of using QScan and QTRouter for cyberattacks against NASA, the Fed, the Senate, and several departments.

2 minutes

Add DEMÓCRATA to Google

Published

2 minutes

The United States Department of Justice and the Federal Bureau of Investigation (FBI) reported this Wednesday the seizure of several Internet domains linked to "two complementary hacking platforms" that, according to Washington, were developed by a group backed by the Government of China and allegedly used in cyberattacks against the National Aeronautics and Space Administration (NASA), the Federal Reserve (Fed), the Senate, and various departments of the U.S. Executive.

"The Department of Justice and the FBI announced today (Wednesday) the seizure of domains, authorized by a court, to prevent cybercriminals from accessing two complementary hacking platforms, known as 'QScan' and 'QTRouter', used to attack the critical infrastructure of the United States and other sensitive networks," reads the statement released by the Justice Department.

The department led by Attorney General Todd Blanche and the FBI state in that note that "a group backed by the State of the People's Republic of China (PRC), known as 'QTFY' and employed by the Chinese company Nanjing Xinjiuwei Network Technology Company, created and operated" the now-seized domains.

The official documentation explains that "QScan automatically scans and infects thousands of Internet of Things (IoT) devices worldwide, which are then added to the QTRouter network of devices controlled by QTFY," while specifying that QTRouter functions as an "obfuscation network." Thus, "it allows QTFY and other cybercriminals to hide the Chinese origin of their intrusion activities, as malicious communications appear to originate from computers (such as those compromised by QScan) located outside of China."

According to the court documents cited by the Department of Justice and the FBI, among QTFY's clients are "the Ministry of State Security and the People's Liberation Army of the People's Republic of China."

On the opposite side, U.S. authorities detail that among the victims of the "QTFY cyber intrusions" are "NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the United States Senate."

In light of this situation, the Attorney General has assured that these "cybercriminals (...) will be arrested and prosecuted." "We are here to ensure the safety of the American people and we will use all the tools at our disposal to fulfill that promise," he stated.

On the other hand, the director of the FBI, Kash Patel, emphasized that this operation "is just the most recent technical operation against hacking sponsored by the People's Republic of China, and in support of the Cyber Strategy for the United States of President Trump, the FBI is intensifying its efforts to influence the behavior of the adversary and defend national security in cyberspace."