The U.S. Department of Justice and the FBI announced Wednesday they have disrupted a hacking operation based in China responsible for breaching the Federal Reserve, Department of Energy, NASA, the U.S. Senate and the DOJ itself, in addition to other healthcare and telecommunications infrastructure since at least 2018.
What federal agencies describe as a Chinese state-sponsored group known as “QTFY” built and operated two hacking platforms called QScan and QTRouter.
According to court documents cited by the DOJ, QTFY expressly offers computer hacking services to paying customers, which the U.S. government says includes China’s Ministry of State Security and the People’s Liberation Army.
QTFY was employed by the China-based Nanjing Xinjiuwei Network Technology Company.
Wednesday’s announcement indicated federal enforcement teams had seized internet domains used by the QTFY network. The hacker group used those domains to obscure the origin of its hacks by running them through software vulnerabilities in so-called “smart devices” like home routers and security cameras.
“So, instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries — potentially through systems just down the street from the victim’s own network,” explained Brett Leatherman, head of the cyber division of the FBI, in a video detailing the operation posted to the bureau’s website Wednesday.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said newly minted Attorney General Todd Blanche in a statement.
Neither the DOJ nor the FBI offered details regarding the damage to federal agencies from associated intrusions, or the degree to which any active intrusions had been thwarted as a result of the domain seizures.
Get these articles in your inbox
Sign up for our daily newsletter
Get these articles in your inbox
Sign up for our daily newsletter
Because the domains were “hard-coded” into the QScan and QTRouter platform, however, the DOJ said those hacking tools are now inoperable. That does not mean the threat environment facing U.S. critical infrastructure has softened, however.
“This is a significant win, but it should be viewed as a disruption, not the end of the threat,” notes Jeffrey Bernstein, president and managing director of Critical Defence, a digital security, regulatory compliance and crisis management advisory firm.
Lender takeaways
Describing the DOJ’s and FBI’s reported actions as “pulling critical pieces of the machinery out from underneath the operators,” Bernstein says lenders should consider the industrial scale behind cybersecurity threats when developing their own corporate security measures.
“The lesson for mortgage lenders is that these attacks are becoming increasingly industrialized,” Bernstein tells Scotsman Guide in an email. “The actors were using technology to identify and compromise vulnerable devices at scale, then using those devices to disguise where subsequent attacks were actually coming from.”
To use a housing metaphor, the DOJ and FBI did not catch intruders breaking through the front door, so to speak, but instead have done something closer to exterminating an insect infestation.
The government says QTFY activity dates back at least to 2018, with the bot network infecting thousands of devices worldwide. Actual intrusion activity of U.S. critical infrastructure could have begun years earlier.
“Mortgage companies hold enormous amounts of financial, identity and transaction data, and they sit inside a highly interconnected financial ecosystem,” Bernstein says. “They should assume that sophisticated adversaries are continuously looking for a way in, directly or through the technology and vendors around them.”





