Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The Hacker News by The Hacker News
August 31, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 31, 2026Cyber Espionage / IoT Botnet

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.

Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were some of the victims of “computer intrusion activity” orchestrated by QTFY, a state-sponsored group affiliated with the People’s Republic of China (PRC).

In the newly updated statement, the aforementioned agencies have been listed as “among the targets of QTFY.” The update was reported by Reuters over the weekend. 

“Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures,” the DoJ said in a note.

According to the affidavit, QTFY (aka QT AND QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, adding payments from the Ministry of State Security (MSS) suggest that the company conducts malicious cyber activities on behalf of Beijing.

The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors.

Described as a technical quartermaster, QTFY has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. Two of the core products in its arsenal are QScan, a vulnerability scanning and exploitation platform, and QTRouter, which is an obfuscation network.

In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN.

The change in wording is significant as it suggests that while the activity may have targeted a broad range of organizations, only some of them were actually compromised.

The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com), effectively neutralizing the malware’s functions.

Lumen Black Lotus Labs has revealed that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, creating a decentralized botnet of infected IoT devices and leased VPSs that enables them to obscure the true origins of the malicious activity.

QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter.

The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws. The entire architecture underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity.

“By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets,” the affidavit alleged.



Source link

The Hacker News

The Hacker News

Next Post

What the great universities teach us about sovereign AI, and who really owns the agentic record

Recommended.

ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are

ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are

February 5, 2026
Nokia partners with atNorth to support cloud services in Finland

Nokia partners with atNorth to support cloud services in Finland

April 29, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio