FBI says two platforms linked to China were used to hide the origin of attacks
As a result, the court-authorized domain seizures made both platforms inoperable, according to the department. The US Justice Department and the FBI have announced the seizure of internet domains linked to two hacking platforms allegedly used by a China state-sponsored cyber group to target critical infrastructure and sensitive networks.
US authorities said the group’s alleged victims included NASA, the Federal Reserve, the Department of Energy, the Department of Justice and the US Senate. US authorities have linked the platforms to a group known as QTFY, which they say is employed by China-based Nanjing Xinjiuwei Network Technology Company, according to court documents. The compromised devices were then used to make malicious internet traffic appear to come from locations outside China, helping hackers conceal the origin of their activities, according to the Justice Department. “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. The Justice Department said the seized domains were hard-coded into the QScan and QTRouter malware and were needed for important functions, including communication and authentication.
The platforms, known as QScan and QTRouter, were allegedly used to hide the origin of cyberattacks by routing malicious activity through compromised devices around the world. The Justice Department alleged that the group offered hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. “These tools were used by PRC cyber actors to hide the origin of their attacks.

