Officials disrupt Chinese espionage operation that hit multiple federal agencies
U.S. officials have disrupted a Chinese government-backed espionage operation that compromised multiple federal agencies, with the full hacking toolkit seized during the takedown. The attackers maintained undetected access to highly sensitive networks for over eight years using the recovered tools and techniques.
The FBI has disrupted Chinese proxy tools that were used in a widespread hacking campaign targeting multiple U.S. government agencies and infrastructure, including NASA, the Federal Reserve, the US Senate, and the Justice Department. According to the Department of Justice, the compromises affected critical institutions across the federal government, highlighting the scope and sophistication of the operation.
The FBI and Department of Justice disrupted two hacking platforms, QScan and QTRouter, operated by Chinese state-sponsored group QTFY to target U.S. critical infrastructure and sensitive networks. The infrastructure was attributed to actors working for Nanjing Xinjiuwei Network Technology Company, a Chinese entity involved in the data theft operations.
US law enforcement disrupted Chinese state-backed hacking tools that were being used to scan, infect, and exploit IoT devices in targeted attacks against federal agencies including the Federal Reserve, Department of Justice, and Senate. The operation represents a significant enforcement action against state-sponsored cyber infrastructure designed to compromise both government and critical infrastructure targets across multiple sectors.
Researchers have identified infrastructure belonging to an Iran-linked hacking group spread across multiple European and Middle Eastern locations, suggesting an expanded operational footprint in these regions. The discovery of servers and domains associated with the group indicates a potentially wider targeting scope than previously understood for this threat actor.