The FBI has announced the disruption of a key network of Chinese proxy devices employed by a state-sponsored hacking group, QTFY, which is alleged to be affiliated with Nanjing Xinjiuwei Network Technology Company. This operation reveals a significant expansion of the hackers’ reach into American government institutions and critical infrastructure.
On Wednesday, the Department of Justice revealed the takedown of two tools, QTRouter and QScan, used by QTFY. According to prosecutors and an FBI affidavit, the company provided its customers with access to botnets of hacked internet-of-things (IoT) devices and co-opted commercial proxy services. The company’s customers, allegedly including the Ministry of State Security and the People’s Liberation Army, then used these proxy services as relay points to carry out hacking campaigns stretching back as early as 2018, according to US government sources.
The DOJ states that the hackers breached a staggering list of US victim agencies, including NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself. The FBI affidavit details the types of US infrastructure and industries targeted via these proxy networks, including power companies, telecommunications providers, hospitals, financial institutions, and defense contractors – though it does not confirm which entities were successfully breached or to what degree.
“The scale is really gigantic,” says Damon Rouse, a threat intelligence researcher at Lumen Technology’s Black Lotus Labs, who reviewed the FBI’s documentation. ‘This company and these people involved in it have very close ties to the highest levels of the People’s Liberation Army.’
The FBI’s affidavit outlines the specific methods the hackers employed – including hijacking VPN services typically used by Chinese citizens to route around China’s Great Firewall. Proxying Chinese hacking operations through those VPNs created a layer of obfuscation, mixing malicious traffic with benign traffic of Chinese users seeking to access the open internet. ‘It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were co-opting,’ Rouse says.
As a result of the takedown, the FBI and Justice Department have seized key domains hardcoded into QScan and QTRouter. Lumen, a provider of internet backbone services, has stated that it ‘null-routed’ certain domains, rendering them inoperable – including the more recent system of co-opting censorship-bypassing VPNs.
US Attorney General Todd Blanche acknowledged that the hackers’ scope of operations is far from clear. ‘State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,’ he wrote in a statement. ‘We are here to ensure security for the American people and will use every tool we have to keep that promise.’
Rouse notes that the hacking campaigns don’t appear to overlap with China’s Volt Typhoon campaign, which sought to disrupt US power, water, and other military and civilian infrastructure. Instead, he believes the years-long hacking operations focused on more traditional espionage. ‘It was pretty much as broad as you can get, mapping back to what Chinese cyber operations are tasked with in terms of information collection,’ Rouse says.
The disruption of the QTFY proxy network will create a setback for those hacking campaigns and some embarrassment and customer relations problems for the Nanjing Xinjiuwei Network Technology Company, Rouse says. But given the hackers’ flexibility in shifting its methods over the years to find new ways to relay and disguise malicious traffic, Rouse has no doubt that it will adapt and return.
Watch Related Video
Source: Wired




















