DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.

Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were some of the victims of "computer intrusion activity" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China (PRC).

In the newly updated statement, the aforementioned agencies have been listed as "among the targets of QTFY." The update was reported by Reuters over the weekend. 

"Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures," the DoJ said in a note.

According to the affidavit, QTFY (aka QT AND QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, adding payments from the Ministry of State Security (MSS) suggest that the company conducts malicious cyber activities on behalf of Beijing.

The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors.

Described as a technical quartermaster, QTFY has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. Two of the core products in its arsenal are QScan, a vulnerability scanning and exploitation platform, and QTRouter, which is an obfuscation network.

In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN.

The change in wording is significant as it suggests that while the activity may have targeted a broad range of organizations, only some of them were actually compromised.

The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com), effectively neutralizing the malware's functions.

Lumen Black Lotus Labs has revealed that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, creating a decentralized botnet of infected IoT devices and leased VPSs that enables them to obscure the true origins of the malicious activity.

QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter.

The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws. The entire architecture underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity.

"By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets," the affidavit alleged.

source: TheHackerNews