The United States Department of Justice (DoJ) announced on Wednesday a significant disruption of two cyber platforms, QScan and QTRouter, operated by Chinese state-sponsored hackers. These platforms were designed to infiltrate critical U.S. infrastructure and sensitive networks.
Chinese State-Sponsored Cyber Activities
The hacking operations have been linked to a Chinese group known as QTFY, which was employed by Nanjing Xinjiuwei Network Technology Company. This group targeted prominent U.S. institutions, including NASA, the Federal Reserve, and multiple federal departments. Security expert Damon Rouse from Lumen Black Lotus Labs, who monitored these actions for over 18 months, noted that Nanjing Xinjiuwei collaborates with China’s Ministry of State Security and the People’s Liberation Army.
In response to these attacks, Lumen began working with the U.S. Federal Bureau of Investigation (FBI) approximately a year ago. Their research uncovered that the cybercriminals particularly targeted research institutions around the world, exploiting the collaborative nature of scientific communities.
Technical Breakdown of QScan and QTRouter
FBI Director Kash Patel highlighted that the dismantled platforms were tools for Chinese hackers to obscure the origins of their cyber intrusions. QScan was used to scan and infect IoT devices, subsequently integrating them into the QTRouter network. This network consisted of compromised devices and a mix of commercial proxy services and leased virtual private servers (VPSs).
QTRouter served as a clandestine network to mask the true origins of cyber attacks, making it appear as though they originated from locations outside China. This obfuscation was crucial for the hackers to remain undetected within targeted networks.
Impact and Future Implications
With the shutdown of the domains hard-coded into these hacking tools, their operations have been effectively halted. The distributed architecture of these tools included additional components like Fast Labyrinth and QTProxy, which provided a sophisticated relay network to disguise cyber activities.
Since its inception in 2018, QTFY has been involved in developing malicious software, trading exploits, and setting up an obfuscation botnet. Their operations targeted critical U.S. systems, facilitated by connections within China’s cyber-enabling businesses and former military personnel.
Lumen emphasized the industrial scale at which these cyber operations were conducted, indicating a shift toward more organized and anonymous cyber campaigns. The use of legitimate commercial proxy services complicates traditional cybersecurity measures, necessitating new strategies to combat such threats.
