US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday.
The tools were run by China-based Nanjing Xinjiuwei Network Technology Company and used primarily by China’s Ministry of State Security and the People’s Liberation Army, the department said in an affidavit. The targeted agencies included the Federal Reserve, Department of Energy, the DOJ itself, the U.S. Senate and NASA.
QScan was used by hackers to scan and automatically infect internet of things devices around the world, the DOJ said, while QTRouter served as an obfuscation network that allowed malicious actors to conceal the origin of their attacks by making it appear that actions came from any of the infected devices.
The tools allegedly enabled Chinese actors to make it look like the cyberattacks were coming from other countries and in some cases made it seem like the incidents were caused by local attackers.
The tools were used by a state-sponsored group known as “QTFY” that targeted U.S. critical infrastructure and other sensitive networks, the Justice Department said. The affidavit said other victims include the Department of Health and Human Services, the National Institutes of Health and multiple hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
FBI Assistant Director Brett Leatherman said that QTFY exploited devices in more than 130 countries and “operates within a complex network of hackers-for-hire and government clients in China.
