sözaltı news Politics
Politics
EN AZ
China-linked hackers infiltrated US government networks before FBI takedown

China-linked hackers infiltrated US government networks before FBI takedown

foxnews.com 27.08.2026 19:00 4 views
QTFY hackers breached three Energy Department labs and stole data from over 300 organizations before the FBI seized domains powering their platforms.

Chinese state-linked hackers stole sensitive data from more than 300 organizations, including U.S. defense contractors, financial institutions and universities, and breached three Energy Department laboratories, the NIH and an HHS agency before the FBI knocked their hacking platforms offline this week, newly unsealed court records show. The group, known as QTFY, operated through a China-based company that the FBI says sold hacking services to clients including China’s Ministry of State Security and People’s Liberation Army. Former PLA members worked for the company and used military relationships to secure contracts and subcontracts for offensive cyber operations, according to an FBI affidavit.

QTFY paired mass internet scanning with a network of compromised routers, cameras and other internet-connected devices that helped disguise the origin of its attacks. FBI SAYS RUSSIAN HACKERS HIJACKED OLD WI-FI ROUTERS By routing malicious traffic through devices near a victim’s network, the hackers could make attacks blend in with legitimate local traffic and become harder to trace, federal officials said. The Justice Department and FBI seized three domains Wednesday that powered QTFY’s two main platforms: QScan, which hunted for vulnerable systems, and QTRouter, which masked hackers’ identities by routing their traffic through compromised devices.

Federal authorities said the seizures crippled both platforms by cutting off domains used for core communications and authentication. AI IS NOW POWERING CYBERATTACKS, MICROSOFT WARNS On a single day in 2024, QScan processed more than 2 million scanning and penetration-testing tasks, according to the FBI affidavit. The platform contained more than 200 proof-of-concept exploits and searched the internet for vulnerable software, exposed services and other openings hackers could exploit.

"QTFY is another example of how China’s cyber ecosystem has blurred the line between commercial cybersecurity and state-sponsored operations," Aaron Shraberg, senior intelligence team lead at Flashpoint, told Fox News Digital. "The commercialization of that ecosystem has helped turn capabilities that once relied on bespoke tradecraft into tools and services that can be developed, reused and deployed at scale." Federal authorities said QTFY targeted NASA, the Justice Department, the Federal Reserve and Senate systems, along with power companies, hospitals, telecommunications providers, defense contractors and election infrastructure. Fox News Digital has reached out to the Chinese embassy for comment.

In 2019, QTFY tried to break into NASA using a vulnerability in the agency’s virtual private network. The attempt failed because NASA had already patched the flaw, according to the affidavit. A separate FBI, NSA and Cyber National Mission Force advisory said the group scanned Senate and hospital-system networks in March and a U.S. election system in June but failed to gain access.

In May 2024, QTFY exploited a recently disclosed Check Point vulnerability while scanning U.S. power and telecommunications companies and stole data from more than 300 organizations in the United States and abroad, according to the advisory. The government did not name the affected organizations or describe what information was taken. The advisory said victims included U.S. defense contractors, financial institutions and universities.

Extract — continue reading at the source.

Read full story