Justice Department, FBI seize platforms used by China state-sponsored hackers to target U.S. critical infrastructure

The United States Justice Department and the Federal Bureau of Investigation have disclosed that a court in the Southern District of California has ordered the seizure of hacking platforms “QScan” and “QTRouter.”
The Office of Public Affairs in the U.S. Department of Justice, in a statement on Wednesday, stated that the move became necessary following the alleged use of both platforms by China to target critical infrastructure and other sensitive networks in the U.S.
The statement read, “The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.
“As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter.
According to the statement, the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate are among the victims of QTFY computer intrusion.
Speaking on the development, Attorney General Todd Blanche stated that, “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise. Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
In the same vein, FBI Director Kash Patel said, “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. These tools were used by PRC cyber actors to hide the origin of their attacks.
“Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking – and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”
For his part, the Assistant Attorney General for National Security, John Eisenberg, noted that, “Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to the national security. These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.”
While U.S. Attorney for the Southern District of California, Adam Gordon, stated that, “We’re taking the fight to PRC sponsored cybercriminals to protect the critical services Americans rely on every day,” Special Agent in Charge, Mark Remily, of the FBI San Diego Field Office said, “The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure.”
“Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries. We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity,” Mr Remily added.
According to the statement, the disruption is among a series of court-authorised technical operations against indiscriminate hacking activities by China.
The FBI and National Security Agency, also on Wednesday, published a cybersecurity advisory providing indicators of compromise by QTFY based on their analysis of QTFY malicious cyber activity dating back to at least 2018.
In addition, Lumen Technologies’ threat intelligence group, Black Lotus Labs, published a description of QTFY’s tactics, techniques and procedures.
The FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division investigated this hacking activity and led this disruption effort.
We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.
More from Peoples Gazette

Agriculture
FG tasks ECOWAS on leveraging financing strategies for agroecology
The federal government has urged stakeholders in the agriculture and finance sectors in the West Africa region to leverage financing strategies to enhance agroecology practices

Politics
Katsina youths pledge to deliver over 2 million votes to Atiku
“Katsina State is Atiku’s political base because it is his second home.”

NationWide
TCN launches platform to improve Nigeria’s national grid reliability
TCN said the platform also features role-based access, structured data uploads and audit trails aimed at strengthening accountability.

World
South Korean man arrested in Japan after overstaying 15-day visa for 26 years
The arrest of the South Korean national comes as Japan continues to record a huge number of visa overstays.

Economy
Atiku to open Benin, Chad, Niger, Cameroon borders, create alternative ports to Lagos
“All the upcoming young men and women who used to have a capital of N10, 20 million, employing two, three people, all of them went bankrupt and unemployed,” said Mr Abubakar.

Rights
Climate group warns of volatile fossil fuels amid Strait of Hormuz blockade
350.org, a climate campaign group, has warned against fossil fuel inflation amid the continued closure of the Strait of Hormuz due to ongoing U.S.-Iran war.

States
Troops eliminate 21 terrorists, dismantle Boko Haram, ISWAP camp in Adamawa
Mr Goni said the operation was part of sustained efforts to locate and rescue persons abducted by terrorists.

Sport
UEFA opens criminal legal proceedings against FIFA, Infantino over proposed World Cup stake sell-off
UEFA called the FFE a “vehicle for Infantino and that small circle to acquire a permanent stake in and otherwise profit from FIFA’s most valuable assets to the detriment of FIFA.






