Security/ china · hacking · doj · critical-infrastructure

DOJ Says Chinese Hackers Breached NASA, Senate, Federal Reserve

The DOJ seized three domains tied to QTFY, a Chinese state-sponsored group accused of hijacking IoT devices to mask attacks on federal agencies since 2018.

The Justice Department has seized three domains it says a Chinese state-sponsored hacking group used to run a botnet aimed at U.S. critical infrastructure.

The DOJ and FBI announced Wednesday that they had seized qtproxy.xyz, qt-proxy.org, and qt-team.com, domains tied to a group the government calls QTFY. Officials say QTFY built two pieces of malware, QScan and QTRouter, to infect thousands of internet-of-things devices worldwide and route malicious traffic through them, masking its true origin. The FBI says the operation has hit U.S. critical infrastructure since 2018, with targets including NASA, the U.S. Senate, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, and NIH. Investigators tie QTFY to the Nanjing Xinjiuwei Network Technology Company and allege China's Ministry of State Security was a paying customer of the group's access-for-hire system.

That business model is the real story here, not any single break-in. This looks less like a smash-and-grab breach and more like infrastructure-as-a-service for state-backed hacking, sold to at least one government client. Tooling built for hire tends to outlive whoever gets caught, and it can get resold to other buyers long after the headlines fade.

The FBI has been chasing this one since 2019, when a NASA intrusion tied to an already-patched vulnerability pointed investigators toward two Gmail accounts and a phone number with a Chinese country code. Seizing three domains is tidy for a press release. It rarely means the people running the botnet are actually done.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →