China-linked hackers infiltrated US government networks before FBI takedown

China-linked hackers infiltrated US government networks before FBI takedown

Source: Fox News

Summary

The FBI says Chinese state-linked hackers, operating through a company tied to China’s Ministry of State Security and People’s Liberation Army, stole sensitive data from over 300 organizations, including U.S. defense contractors, financial institutions, and universities. The group, known as QTFY, used compromised devices to mask attack origins and breached three Energy Department labs, the NIH, and an HHS agency. The FBI seized domains used by QTFY’s platforms, QScan and QTRouter, disrupting their operations. The Justice Department and FBI said the takedown crippled the group’s ability to conduct cyberattacks.


Our Reading

As expected, the matter has reached another stage.

QTFY used old routers to hide its tracks.

The FBI shut down its platforms with a few clicks.

China’s hackers work through companies that look clean.

Every attack is a test, and some fail, but others work.


Author: Evan Null

Chinese Hacking Group QTFY

QTFY is a group of hackers linked to China’s government. They used a company to hide their work. The FBI found out and stopped their attacks. They stole data from many places, including government agencies and universities. The group used old devices to make their attacks harder to find.

FBI’s Response

The FBI shut down the websites that QTFY used. This made it harder for the hackers to work. The Justice Department helped with the operation. They said the move would stop more attacks. The FBI has done similar things before against other hacking groups.

Impact on U.S. Organizations

Over 300 organizations were affected. These included defense contractors, banks, and schools. Some attacks worked, and some didn’t. The hackers tried to break into NASA, but they failed. They also tried to get into election systems, but didn’t succeed.

How the Hacking Worked

QTFY used a method called “mass internet scanning.” They looked for weak spots in computer systems. They also used compromised devices to hide where the attacks came from. This made it hard to find the real source of the hacking.

Previous Hacking Operations

The FBI has taken down other hacking groups before. In 2023, they stopped a group called Volt Typhoon. In 2022, they removed a botnet used by another group. These operations show the FBI is working to stop cyber threats from China.