US seizes domains targeting NASA and Fed hacks
In a high-stakes operation that shook the foundations of digital security, the U.S. Department of Justice and the FBI recently announced the seizure of domains linked to platforms allegedly operated by China state-sponsored hackers. This action underscores the persistent, sophisticated threat posed by foreign actors targeting America’s most vital systems.
The intrusion activity was not isolated; it touched nearly every facet of the nation’s digital architecture. The press release detailed that various critical entities—including the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, NASA, and the U.S. Senate—had all experienced computer intrusion.
At the center of this digital disruption was a state-sponsored group known as QTFY. Authorities claim this group leveraged two distinct pieces of malware, QTRouter and QScan, to execute their malicious campaigns. The QScan system was designed to scan and automatically infect thousands of Internet of Things (IoT) devices globally, creating a vast botnet that the government referred to as an obfuscation layer to mask the origin of malicious traffic.
The scope of the damage reached deep into the infrastructure. According to investigations, QTFY’s system was allegedly used to compromise U.S. critical infrastructure as early as 2018. The group is reportedly linked to the Nanjing Xinjiuwei Network Technology Company, though specific details on this entity remain elusive.
The hunt for these digital footprints began as early as 2019, when the FBI traced initial activity back to a system intrusion at NASA related to the CVE-2019-11510 vulnerability. The investigation quickly led the authorities to two Gmail accounts and a phone number utilizing the +86 country code, a clear indicator of the People’s Republic of China.
Further tracing revealed that the group allegedly rented infrastructure from commercial platforms, resulting in numerous abuse complaints filed against hosting providers. The seized domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—were reportedly obtained between 2022 and 2024 and registered through Namecheap, paid for via PayPal.
While the People’s Republic of China routinely denies involvement in hacking activities within the United States, recent developments suggest a shift in official stance. Chinese officials have reportedly acknowledged that the government was behind a series of attacks on U.S. infrastructure late last year. Furthermore, reports indicate that in 2024, Chinese attackers reportedly compromised 30-year-old wiretap systems deployed by U.S. telecom and internet providers, underscoring the enduring complexity of this geopolitical digital battle.