U.S. officials announced the disruption of a Chinese hacking operation believed to be responsible for cyber break-ins at several sensitive federal agencies, according to a statement from the Justice Department. The operation allegedly targeted the Departments of Justice and Energy, as well as NASA, the Federal Reserve, the Senate, and other government entities.
In court documents unsealed in the Southern District of California, the Justice Department stated it seized internet domains used by two hacking platforms named QScan and QTRouter. These platforms were reportedly used by a state-sponsored group known as QTFY, which is employed by the China-based Nanjing Xinjiuwei Network Technology Company, to penetrate U.S. target networks and conceal their tracks.
According to the documents, QTFY offers hacking services to customers including China's Ministry of State Security and the People's Liberation Army. The QScan platform reportedly scans and infects thousands of internet-of-things devices, which are then added to the QTRouter network to serve as an obfuscation network to hide the origin of the intrusions.
Attorney General Todd Blanche stated that federal law enforcement investigated and disabled the malicious software to ensure security for the American people. FBI Director Kash Patel noted the bureau played a key role in disrupting the global botnet and hacking platform used to target U.S. critical infrastructure.
The Chinese embassy in Washington said it firmly opposes and combats all forms of cyberattacks in accordance with the law, and urged the U.S. to stop using cybersecurity issues to discredit China. The embassy also stated it will safeguard the legitimate rights and interests of Chinese companies in response to U.S. punitive restrictions.
Former senior DOJ attorney Michael Lebowitz suggested the public disclosure of the scheme resembles a name-and-shame campaign intended to alert foreign hackers that their activities have been detected. Mieke Eoyang, a former deputy assistant secretary of Defense for Cyber Policy, noted that Chinese hacking activities are pervasive and sophisticated, operating at a scale few other countries can match.