Table of Contents
Why Did the DOJ and FBI Seize Platforms Used by Chinese hackers?
Federal authorities dismantled tools used by Chinese hackers to target U.S. critical infrastructure and sensitive government networks.
The Justice Department and FBI announced court-authorized domain seizures that disabled two complementary hacking platforms known as QScan and QTRouter. Court documents unsealed in the Southern District of California state that a People’s Republic of China state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company, created and operated the platforms. The tools were used to target U.S. critical infrastructure and other sensitive networks while concealing the origin of attacks.
Seizure of QScan and QTRouter Platforms
Because the seized domains were hard-coded into both platforms and used for communication and authentication, the seizures rendered QScan and QTRouter inoperable. Officials described the action as part of a series of technical operations against indiscriminate hacking activities sponsored by the People’s Republic of China. FBI Director Kash Patel said the disruption targeted a global botnet and hacking platform used against U.S. critical infrastructure.
Agencies and Networks Targeted by Intrusions
NASA, the Department of Energy, Federal Reserve, US Senate, and the DOJ themselves were among those hit by Chinese hackers. Court filings also list the Department of Health and Human Services and the National Institutes of Health among victims of QTFY computer intrusion activity. Additional targeted networks included those operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
Official Statements and Strategic Purpose
Attorney General Todd Blanche stated that state-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted, and that federal law enforcement investigated and disabled the PRC’s malicious software. The operation supports President Trump’s Cyber Strategy for America. Officials said the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.
Implications for U.S. Critical Infrastructure Defense
The seizures deny the actors access to infrastructure they relied upon to conduct and conceal computer intrusions. By dismantling hard-coded command channels, authorities interrupted an active capability used against both government and private-sector networks. The action demonstrates continued use of court-authorized technical operations to impose costs on PRC-sponsored cyber actors.
Disrupting platforms operated by Chinese hackers reduces the ability of state-sponsored groups to blend malicious traffic with legitimate activity and to persist inside sensitive American networks. Coordinated DOJ and FBI operations remain a central tool for defending critical infrastructure against campaigns by Chinese hackers.
Read more: https://morsereport.com/a/news/iranian-hackers-shut-down-uk-power-plant-for-four-days
Republic Trucker Hat - Navy / White
$45.00
SHIPPING FOREWORD: Because all Morse Report products are 100% sourced and manufactured inside of the United States of America at the highest standard of excellence, shipping fulfillment can take anywhere from 5 - 14 days, depending on conditions. THANK YOU!… read more
FAQs
Why Did the DOJ and FBI Seize Platforms Used by Chinese hackers?
Federal authorities dismantled tools used by Chinese hackers to target U.S. critical infrastructure and sensitive government networks.
The Justice Department and FBI announced court-authorized domain seizures that disabled two complementary hacking platforms known as QScan and QTRouter. Court documents unsealed in the Southern District of California state that a People’s Republic of China state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company, created and operated the platforms. The tools were used to target U.S. critical infrastructure and other sensitive networks while concealing the origin of attacks.