The United States Department of Justice (DoJ) recently amended a prior announcement concerning cyber activities allegedly conducted by Chinese operatives. Initially described as victims, several U.S. agencies, including NASA and the Federal Reserve, were clarified to be among the targets of these attempts.
DoJ’s Revised Announcement
Last week, the DoJ’s press release listed major U.S. organizations as victims of cyber intrusions attributed to QTFY, a hacker group linked to China’s government. However, the updated statement has refined this to indicate these entities were targeted rather than directly compromised, as reported by Reuters.
This correction was made to ensure the press release accurately mirrored the allegations detailed in the affidavit supporting actions like domain seizures. The affidavit identifies QTFY as operating under a Chinese company, Nanjing Xinjiuwei Network Technology Co, and suggests possible sponsorship by the Ministry of State Security for conducting cyber attacks.
Scope of Cyber Activities
Active since 2018, QTFY has engaged in compromising critical infrastructure across the U.S. and internationally. The group’s targets span federal networks, hospitals, telecom companies, and defense contractors. The group’s technical capabilities include reconnaissance and operational routing to aid cyber espionage, using tools like QScan and QTRouter.
In a notable 2019 incident, QTFY reportedly attempted to breach NASA by exploiting a vulnerability in Pulse Secure VPN. The nuanced wording in the DoJ’s update suggests that although there was a wide range of targets, only a subset was successfully infiltrated.
Countermeasures and Ongoing Threats
The FBI has intervened by disrupting domains associated with QTFY’s tools, QScan and QTRouter, thereby hindering the malware’s operation. However, threat intelligence from Lumen Black Lotus Labs indicates that QTFY has developed ORB networks to support China-linked espionage, using IoT devices and leased servers to obfuscate attack origins.
QTFY not only leverages these tools internally but also sells access to other malicious actors. This commercialization enables the creation of widespread botnets, complicating efforts to trace and mitigate their activities. Fastlink.ws, a Chinese proxy service, further enhances this network by providing nodes that facilitate the Fast Labyrinth, an encrypted relay network blending malicious and legitimate traffic.
The affidavit highlights that by routing attacks through compromised local IoT devices, the group can disguise their activities within normal network traffic, making detection challenging. This strategy underscores the sophisticated methods employed by QTFY in its ongoing cyber espionage efforts.
