Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
The U.S. Justice Department and FBI seized two hacking platforms, QScan and QTRouter, used by a China state-sponsored group to target critical U.S. infrastructure, including NASA, the Federal Reserve, and the Senate.
The Justice Department and FBI announced the seizure of QScan and QTRouter, two hacking platforms operated by a China state-sponsored group identified as QTFY, which targeted U.S. critical infrastructure and sensitive networks. The platforms were used to compromise thousands of internet-of-things devices worldwide, enabling the group to conceal the origin of their cyberattacks. The seizures were authorized by a federal court in the Southern District of California, rendering the platforms inoperable.
The platforms, QScan and QTRouter, worked in tandem to infect and control devices, including IoT devices, commercial proxy services, and virtual private servers. QScan automatically infected devices, which were then integrated into QTRouter’s network to obscure the origin of malicious activities. The seized domains were critical to the platforms’ operation, disabling their functionality. Victims included NASA, the Federal Reserve, the Department of Energy, and the U.S. Senate, among others.
Attorney General Todd Blanche stated that the operation reflects the government’s commitment to prosecuting state-sponsored hackers targeting American infrastructure. FBI Director Kash Patel emphasized that the disruption aligns with broader efforts to dismantle China’s hacking activities, including previous operations against groups like Mustang Panda and Flax Typhoon. Assistant Attorney General John A. Eisenberg highlighted the Justice Department’s offensive approach to countering cyber threats to national security.
The FBI and National Security Agency also published a cybersecurity advisory detailing QTFY’s malicious activities dating back to 2018, alongside threat intelligence from Lumen Technologies’ Black Lotus Labs. The investigation was led by the FBI’s San Diego Field Office, Cyber Division, and the U.S. Attorney’s Office for the Southern District of California, with support from the Justice Department’s National Security Cyber Section.