How China industrialized the infrastructure behind state hacking
Brief
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.
A People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by a corporation called China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.
Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and US Senate.
The law enforcement agencies said QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army.
