WASHINGTON — Chinese state-sponsored hackers infiltrated US government computer networks ranging from NASA to the US Senate before having web domains linked to their malicious cyber group shut down by the feds.
The Department of Justice and FBI announced on Wednesday the seizure of three domains linked to Chinese state-sponsored hacking group QTFY, which had been used “to compromise critical infrastructure and other sensitive networks,” according to an FBI affidavit.
Since 2018, an FBI special agent wrote in the affidavit, QTFY had succeeded in breaching networks at NASA, NIH, the DOJ, the Department of Health and Human Services, three Department of Energy National Laboratories, the Federal Reserve and the Senate.
The affidavit alleged that the hackers’ domains were facilitating an international money laundering conspiracy.
Attorney General Todd Blanche told Fox News the hackers were also targeting “hospital systems and health care centers.”
The newly released documents show the Chinese hackers infiltrated the government systems between 2018 and 2026, but provide few details on what the cyber criminals were searching for and if they were successful in inflicting harm.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Blanche also said in a statement.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
QTFY sold access to its computer hacking services — known as “QScan” and “QTRouter” — to the Chinese Ministry of State Security and the People’s Liberation Army via a private company called Nanjing Xinjiuwei Network Technology Co.
The services were able to infect thousands of devices across the globe. The affidavit cites in particular a medical center in Ohio, financial groups in Michigan and South Korea and an insurance agency in Missouri.
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” added FBI Director Kash Patel in a statement.
“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down,” Patel said.
“Today’s action is just the latest technical operation against PRC-sponsored hacking – and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”
Read the full article here
