DOJ: Chinese Hackers Targeted U.S. Infrastructure

Federal authorities have disrupted a Chinese state-sponsored hacking operation that targeted critical infrastructure across the United States, including networks operated by power companies, hospitals, telecommunications providers, financial institutions and defense contractors.

The Justice Department and FBI announced Wednesday that they seized internet domains supporting two hacking platforms known as QScan and QTRouter. Federal investigators linked the systems to a group known as QTFY, which operates through China-based Nanjing Xinjiuwei Network Technology Company. According to court documents, the company has provided hacking services to customers that include China’s Ministry of State Security and People’s Liberation Army.

While the Justice Department’s announcement broadly described the targets as U.S. critical infrastructure and sensitive networks, an FBI affidavit unsealed in federal court provides additional details. Investigators said QTFY infrastructure has been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and around the world. The affidavit specifically identifies networks operated by power companies, hospitals, telecommunications providers, financial institutions and defense contractors among those targeted.

Federal government networks were also targeted. Authorities identified NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate among victims of QTFY computer intrusion activity.

The hackers allegedly used QScan to search the internet for vulnerable devices and automatically compromise thousands of Internet-of-Things devices around the world. Those devices could then become part of QTRouter, a network designed to disguise where hacking activity originated. By routing communications through compromised devices, proxy services and leased servers, activity originating with Chinese cyber actors could appear to be coming from another country or even from a device located near the network being targeted.

The disclosure that power companies were among the targets does not mean federal authorities have determined that hackers gained control of the U.S. electric grid. The court documents identify power-company networks as targets but do not establish that electric-grid operational systems were compromised, manipulated or used to cause power outages.

Federal authorities were able to disrupt the operation because domains necessary for QScan and QTRouter were built directly into the platforms. Once those domains were seized under court authorization, the systems could no longer perform essential communication and authentication functions, rendering the platforms inoperable, according to the Justice Department.

The operation follows several previous federal actions against Chinese state-sponsored cyber infrastructure, including disruptions involving Volt Typhoon, Flax Typhoon and Mustang Panda. The FBI and National Security Agency have also released technical information designed to help organizations determine whether their networks were affected by QTFY activity.

About First State Update News Room

First State Update’s Delaware editorial team delivers dynamic, around-the-clock coverage of breaking news, politics, and major developments across Delaware and the surrounding region. We're are on the ground bringing readers fast, accurate updates on the stories shaping Delaware. Have news to share or a tip to pass along? Email us at [email protected] or send us a message on Facebook.

View all posts by First State Update News Room →