Justice Department seizes QTFY’s QScan and QTRouter after listing NASA, the Fed, and the Senate
The press release lists NASA, the Fed, and the Senate as victims. The disruption is three domains that made two platforms inoperable.
The Justice Department and FBI announced court-authorized domain seizures Wednesday in the Southern District of California. A PRC state-sponsored group known as QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated two complementary platforms, QScan and QTRouter. The release lists, among the victims of “QTFY computer intrusion activity,” NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate.
ABC News‘s Alexander Mallin and Luke Barr, reading the unsealed court file, write that the documents do not state clearly the scale of the attacks against several of the other government agencies identified as victims, or the group’s level of success in infiltrating specific networks. The group is alleged to have attempted a hack against NASA in 2019. Court documents do not suggest that effort was successful.
CyberScoop, working from the same affidavit, says a March attempt on the Senate was unsuccessful, and that QTFY also attempted, unsuccessfully, to gain access to a US election system in June.
The seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication. Because of that, the court-authorized seizures made QScan and QTRouter inoperable.
QTFY offers computer hacking services to paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. QScan and QTRouter work in conjunction.
QScan scans and automatically infects thousands of IoT devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of those compromised IoT devices, commercial proxy service devices, and leased virtual private servers.
The Justice Department calls QTRouter an “obfuscation network.” Malicious communications appear to originate from computers outside the PRC, and may even be local to the targeted networks.
QScan was built for volume. CyberScoop, citing a special agent for the FBI in the affidavit, says the scanner included more than 200 proof-of-concept exploits, and that on a single day in 2024 it processed over two million scanning and exploit tasks.
In September 2024, CyberScoop reports, the group exploited multiple Ivanti zero-day vulnerabilities to intrude the networks of three Energy Department national laboratories, NIH, an HHS agency, and a US-based security device manufacturer. Officials said the seized domains were used in those attacks. The seizure warrant, via ABC, uses the phrase “conducted computer intrusions” for that September set.
ABC also writes that QTFY includes former members of China’s military, and that the infrastructure has been used against networks spanning government agencies, hospitals, telecommunications providers, power companies, and defense contractors. Hundreds of entities, in ABC’s phrasing.
The FBI and NSA published a cybersecurity advisory with indicators of compromise, based on analysis of QTFY activity dating back to at least 2018. CyberScoop says the FBI has been investigating the group since at least 2019.
The hide was for sale.
