news.mlab.sh
Back to the feed
threat-intel

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

CriticalCVSS 10.0
Summary

The U.S. Department of Justice has corrected a previous statement, clarifying that its agencies were targeted by Chinese threat actors (QTFY) as part of a broader espionage campaign, rather than being victims of a successful attack. The DoJ’s update, following FBI disruption of associated domains, reveals that QTFY, operating on behalf of the Chinese Ministry of State Security, has been actively targeting critical infrastructure and sensitive networks globally, utilizing tools like QScan and QTRouter to identify and exploit vulnerable IoT devices.

The U.S. Department of Justice (DoJ) has revised its previous statement regarding Chinese cyber espionage activities. Initially, the DoJ indicated that several U.S. agencies, including the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate, were victims of ‘computer intrusion activity’ orchestrated by Chinese threat actors, specifically QTFY (also known as QT AND QTCYBER). However, the DoJ now states that these agencies were ‘among the targets’ of QTFY’s operations, suggesting that while they were identified as potential targets, not all were successfully compromised.

QTFY, operating on behalf of the Chinese Ministry of State Security (MSS), has been active since 2018 and utilizes tools such as QScan (a vulnerability scanning and exploitation platform) and QTRouter (an obfuscation network) to identify and exploit vulnerable IoT devices. The FBI has taken action, disrupting the domains associated with QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com).

Lumen Black Lotus Labs has uncovered that QTFY has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, establishing a decentralized botnet of infected IoT devices and leased VPSs. These networks enable the concealment of malicious activity by routing internet traffic through compromised devices located near victims, effectively blending it with legitimate user traffic.

The entire architecture underpins Fast Labyrinth, an encrypted relay network that further obscures the origins of malicious internet traffic. QTFY sells access to QScan and QTRouter to other actors, allowing them to identify and exploit vulnerable IoT devices, which are then enlisted as botnet nodes within the QTRouter network. The network also incorporates nodes operated by the Chinese commercial proxy service fastlink[.]ws.

Read the full article at The Hacker News