As cited
Copy frozen at (site build).
threat intel
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
The FBI disrupted a Chinese government-backed hacking operation called QTFY that had compromised U.S. government networks and critical infrastructure since at least 2018. The bureau seized three domains supporting QScan malware and the QTRouter botnet, which scanned for vulnerabilities and provided obfuscation services. Targets included NASA, the Senate, the Department of Energy, the Federal Reserve, and multiple other federal agencies; the Justice Department later clarified these were targeted rather than confirmed compromised systems.
Why it matters: Federal agencies and critical infrastructure operators must audit systems for compromise via CVE-2019-11510, CVE-2019-19781, and CVE-2024 Ivanti Cloud Services Appliance vulnerabilities, and monitor for residual QTFY access or related Chinese state-sponsored intrusion activity affecting their networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
The FBI disrupted a Chinese government-backed hacking operation called QTFY that had compromised U.S. government networks and critical infrastructure since at least 2018. The bureau seized three domains supporting QScan malware and the QTRouter botnet, which scanned for vulnerabilities and provided obfuscation services. Targets included NASA, the Senate, the Department of Energy, the Federal Reserve, and multiple other federal agencies; the Justice Department later clarified these were targeted rather than confirmed compromised systems.
Why it matters: Federal agencies and critical infrastructure operators must audit systems for compromise via CVE-2019-11510, CVE-2019-19781, and CVE-2024 Ivanti Cloud Services Appliance vulnerabilities, and monitor for residual QTFY access or related Chinese state-sponsored intrusion activity affecting their networks.
- Source published
- First seen by Cybersecurity Tracker