Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DoJ Revises China Hacking Statement, Targets Identified

DoJ Revises China Hacking Statement, Targets Identified

Posted on August 31, 2026 By CWS

The United States Department of Justice (DoJ) recently amended a prior announcement concerning cyber activities allegedly conducted by Chinese operatives. Initially described as victims, several U.S. agencies, including NASA and the Federal Reserve, were clarified to be among the targets of these attempts.

DoJ’s Revised Announcement

Last week, the DoJ’s press release listed major U.S. organizations as victims of cyber intrusions attributed to QTFY, a hacker group linked to China’s government. However, the updated statement has refined this to indicate these entities were targeted rather than directly compromised, as reported by Reuters.

This correction was made to ensure the press release accurately mirrored the allegations detailed in the affidavit supporting actions like domain seizures. The affidavit identifies QTFY as operating under a Chinese company, Nanjing Xinjiuwei Network Technology Co, and suggests possible sponsorship by the Ministry of State Security for conducting cyber attacks.

Scope of Cyber Activities

Active since 2018, QTFY has engaged in compromising critical infrastructure across the U.S. and internationally. The group’s targets span federal networks, hospitals, telecom companies, and defense contractors. The group’s technical capabilities include reconnaissance and operational routing to aid cyber espionage, using tools like QScan and QTRouter.

In a notable 2019 incident, QTFY reportedly attempted to breach NASA by exploiting a vulnerability in Pulse Secure VPN. The nuanced wording in the DoJ’s update suggests that although there was a wide range of targets, only a subset was successfully infiltrated.

Countermeasures and Ongoing Threats

The FBI has intervened by disrupting domains associated with QTFY’s tools, QScan and QTRouter, thereby hindering the malware’s operation. However, threat intelligence from Lumen Black Lotus Labs indicates that QTFY has developed ORB networks to support China-linked espionage, using IoT devices and leased servers to obfuscate attack origins.

QTFY not only leverages these tools internally but also sells access to other malicious actors. This commercialization enables the creation of widespread botnets, complicating efforts to trace and mitigate their activities. Fastlink.ws, a Chinese proxy service, further enhances this network by providing nodes that facilitate the Fast Labyrinth, an encrypted relay network blending malicious and legitimate traffic.

The affidavit highlights that by routing attacks through compromised local IoT devices, the group can disguise their activities within normal network traffic, making detection challenging. This strategy underscores the sophisticated methods employed by QTFY in its ongoing cyber espionage efforts.

The Hacker News Tags:affidavit, China hacking, cyber attacks, cyber espionage, cyber threats, Cybersecurity, DoJ, FBI, IoT botnet, QScan, QTFY, QTRouter, U.S. agencies

Post navigation

Previous Post: PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities
Next Post: Security Vulnerability in Composer Exposes Sensitive Files

Related Posts

Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution The Hacker News
U.K. Government Drops Apple Encryption Backdoor Order After U.S. Civil Liberties Pushback U.K. Government Drops Apple Encryption Backdoor Order After U.S. Civil Liberties Pushback The Hacker News
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign The Hacker News
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps The Hacker News
FBI Alerts Law Firms to Luna Moth’s Stealth Phishing Campaign FBI Alerts Law Firms to Luna Moth’s Stealth Phishing Campaign The Hacker News
CDN Tsunami Threat: HTTP/3 Amplification in Focus CDN Tsunami Threat: HTTP/3 Amplification in Focus The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Vulnerability in Composer Exposes Sensitive Files
  • DoJ Revises China Hacking Statement, Targets Identified
  • PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities
  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Vulnerability in Composer Exposes Sensitive Files
  • DoJ Revises China Hacking Statement, Targets Identified
  • PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities
  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark