🇺🇸🇺🇸👮❌🇨🇳👺 — FBI knocks China-linked QScan and QTRouter hacking infrastructure offline
➡️ The DOJ and FBI seized domains powering two hacking platforms operated by QTFY, a Chinese state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company.
In Statement the DOJ said:
The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter. Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” said Attorney General Todd Blanche. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”
“Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to the national security,” said Assistant Attorney General for National Security John A. Eisenberg. “These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.
”
“We’re taking the fight to PRC sponsored cybercriminals to protect the critical services Americans rely on every day,” said U.S. Attorney Adam Gordon for the Southern District of California.
“The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure,” said Special Agent in Charge Mark Remily of the FBI San Diego Field Office. “Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries. We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”