US Says Chinese Hackers Breached NASA, Senate In Major Cybersecurity Attack

Washington: US authorities have disrupted an alleged Chinese state-sponsored hacking operation that targeted sensitive American institutions, including NASA, the US Senate and the Federal Reserve, the Justice Department said.
The US Justice Department and FBI announced that they had seized internet domains allegedly used by a Chinese hacking group known as QTFY. Officials said the operation relied on two platforms, QScan and QTRouter, to conduct cyberattacks against organisations in the US and other countries.
According to court documents cited by the Justice Department, QTFY allegedly provided hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. The group was reportedly employed by Nanjing Xinjiuwei Network Technology Company, a China-based technology firm.
The alleged victims included NASA, the Federal Reserve, the US Senate, and the departments of Energy, Justice, and Health and Human Services.
The hackers also reportedly targeted a wide range of private-sector organisations, including hospitals, universities, telecommunications companies, power utilities, financial institutions and defence contractors.
How The Alleged Hacking Operation Worked
Court documents described QScan as a tool that automatically searched for vulnerable internet-connected devices and infected thousands of systems around the world.
Those compromised devices were then reportedly added to QTRouter, a network controlled by the hackers. The operation also allegedly relied on commercial proxy services and rented virtual private servers to hide the true origin of the attacks.
As a result, malicious traffic could appear to come from compromised computers located outside China — sometimes even from systems located close to the intended target.
US officials said the domains seized during the operation were critical to the functioning of both platforms. They were reportedly used for communication, authentication and other essential operations.
By taking control of those domains, authorities were able to disrupt the infrastructure supporting QScan and QTRouter, effectively rendering the platforms inoperable.
FBI Calls It A Major Disruption
Attorney General Todd Blanche said the operation was part of a broader effort by US law enforcement to dismantle what Washington describes as malicious cyber activity sponsored by the People’s Republic of China.
FBI Director Kash Patel said the operation disrupted a global botnet and hacking platform allegedly used by Chinese state-sponsored hackers to target critical US infrastructure.
The FBI and National Security Agency have also released a cybersecurity advisory containing technical indicators that organisations can use to identify possible QTFY-related activity.
The allegations underscore the growing cybersecurity threat facing government agencies and critical infrastructure, as authorities increasingly focus on sophisticated hacking networks capable of disguising their origins and compromising systems across multiple sectors.
News Source : Information for this article was gathered from a variety of reliable news outlets.

