DistantNews
Support us
China-linked hackers targeted NASA, US Fed; Korean firms also hit
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Technology

China-linked hackers targeted NASA, US Fed; Korean firms also hit

From Dong-A Ilbo · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

News Named sources Outcome reported
  • A China-linked hacking group, 'QTFY,' targeted major U.S. institutions including NASA and the Federal Reserve for years.
  • Four Korean companies were among the victims, though their names were not disclosed.
  • U.S. authorities seized key domains used by the hacking platform, disrupting its operations.

U.S. authorities have dismantled a sophisticated cyberespionage campaign orchestrated by a China-linked hacking group, identified as 'QTFY.' For years, this group targeted key U.S. government agencies, including NASA, the Federal Reserve, the Department of Justice, and the Senate, as well as critical infrastructure.

The operation, led by the U.S. Department of Justice and the FBI, resulted in the seizure of core domains associated with QTFY's hacking platforms, 'QScan' and 'QTRouter.' This action has rendered the platforms inoperable, significantly disrupting the group's ability to conduct cyberattacks. Court documents revealed that four companies in South Korea were also victims of QTFY's activities, alongside unspecified U.S. businesses.

We will deter and prosecute nation-state hackers targeting America's critical infrastructure.

โ€” Todd BlancheU.S. Attorney for the Southern District of New York, emphasizing the U.S. commitment to combating state-sponsored cyberattacks.

QTFY, reportedly based in Nanjing, China, operated as a commercial hacking service provider, with clients including China's Ministry of State Security and the People's Liberation Army. The group utilized QScan to identify and infect Internet of Things (IoT) devices globally, commandeering them into a botnet managed by QTRouter. This latter platform masked the attackers' true location by routing traffic through compromised IoT devices and rented servers, making it appear as though attacks originated from different countries.

U.S. officials believe QTFY has been active since at least 2018, employing custom-developed tools to infiltrate sensitive networks. While not all attempted intrusions resulted in successful data breaches, investigations confirmed successful infiltrations into U.S. research labs, government agencies, and a medical network in 2024. The U.S. has recently undertaken several operations to neutralize cyberattack infrastructure linked to Chinese government-backed groups, including previous actions against 'Mustang Panda,' 'Flax Typhoon,' and 'Volt Typhoon.'

China's embassy in the U.S. spokesperson stated that China firmly opposes and combats all forms of cyberattacks in accordance with the law.

โ€” Chinese Embassy spokespersonResponding to the U.S. allegations, the Chinese embassy denied involvement and asserted China's stance against cyberattacks.
About this summary

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.