CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5895

As cited

Copy frozen at (site build).

threat intel

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

The FBI disrupted a Chinese government-backed hacking operation called QTFY that had compromised U.S. government networks and critical infrastructure since at least 2018. The bureau seized three domains supporting QScan malware and the QTRouter botnet, which scanned for vulnerabilities and provided obfuscation services. Targets included NASA, the Senate, the Department of Energy, the Federal Reserve, and multiple other federal agencies; the Justice Department later clarified these were targeted rather than confirmed compromised systems.

Why it matters: Federal agencies and critical infrastructure operators must audit systems for compromise via CVE-2019-11510, CVE-2019-19781, and CVE-2024 Ivanti Cloud Services Appliance vulnerabilities, and monitor for residual QTFY access or related Chinese state-sponsored intrusion activity affecting their networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

The FBI disrupted a Chinese government-backed hacking operation called QTFY that had compromised U.S. government networks and critical infrastructure since at least 2018. The bureau seized three domains supporting QScan malware and the QTRouter botnet, which scanned for vulnerabilities and provided obfuscation services. Targets included NASA, the Senate, the Department of Energy, the Federal Reserve, and multiple other federal agencies; the Justice Department later clarified these were targeted rather than confirmed compromised systems.

Why it matters: Federal agencies and critical infrastructure operators must audit systems for compromise via CVE-2019-11510, CVE-2019-19781, and CVE-2024 Ivanti Cloud Services Appliance vulnerabilities, and monitor for residual QTFY access or related Chinese state-sponsored intrusion activity affecting their networks.

VendorsIvantiCitrix
Actorsvolt typhoonmustang panda
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary