US seizes domains it says Chinese hackers use to target critical infrastructure

US seizes domains it says Chinese hackers use to target critical infrastructure

The DOJ says it seized two domains used by a Chinese state-sponsored hacking group to target critical infrastructure and sensitive networks in the U.S.SAN DIEGO (CN) — Two internet domains the Department of Justice says were being used by state-sponsored Chinese hackers to target critical infrastructure in the United States were seized under a court order, the department said in a Wednesday release.A San Diego federal judge authorized the domain seizure to deny malicious actors access to platforms used for cyberattacks: QScan and QTRouter. The state-sponsored hacker group QTFY created and used the two platforms to scan vulnerable devices and hide malicious network traffic, an FBI agent said in an affidavit in support of the domain seizures.Officials from the Trump administration described the seizures as a victory in what is often described as a cyber cold war between the United States and China.“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said in the release. “We are here to ensure security for the American people and will use every tool we have to keep that promise. Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”The QTFY platforms have been used to compromise U.S. critical infrastructure going back to at least 2018, the FBI agent said. QTFY used the platforms to spy on government agencies, including NASA, the Federal Reserve, the Department of Energy, the DOJ and the Senate, among others, the DOJ said in the release.QScan scanned and automatically infected thousands of vulnerable devices worldwide, which were then added to the QTRouter network, the agent said in the affidavit.QTFY then put these devices into service through its network of infected devices, or “bots,” which can be remotely controlled for a variety of tasks. The devices may even be located within the targeted networks — such as a government employee’s computer.In this case, the botnets were used to obscure QTFY’s actions and its Chinese origin, the DOJ said in the release.QTFY, which the DOJ says is employed by the Nanjing Xinjiuwei Network Technology Company, offered these platforms as branded services to customers. Those customers include the Chinese military and China’s Ministry of State Security, a government advisory on QTFY also said Wednesday.Lumen Technologies, which also issued a report today, describes the hacker group as operating under a quartermaster model, providing the infrastructure to identify targets, route malicious traffic and obscure its activity.The domains were vital parts of the QScan and QTRouter technology, rendering them inoperable after the court-ordered domain seizure, the DOJ said in its release.“These tools were used by People’s Republic of China cyber actors to hide the origin of their attacks,” FBI Director Kash Patel also said in the release. “Today’s action is just the latest technical operation against PRC-sponsored hacking — and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”The DOJ touted the seizure as the latest victory in a series of technical operations targeting China’s state-sponsored hacking activities over the past few years.In the affidavit, the FBI agent said there is probable cause to believe the domains were involved in a money laundering scheme.“Through complex investigations, aggressive technical operations and strong partnerships, FBI San Diego will continue to identify, disrupt and impose costs on our cyber adversaries,” FBI San Diego Field Office Special Agent in Charge Mark Remily said. “We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”The seizures are part of a broader, unseen conflict between the United States and China as hackers from both sides work to gather intelligence and embed themselves in each other’s critical infrastructure. The Cybersecurity and Infrastructure Security Agency has long warned that Chinese hackers have targeted infrastructure like telecommunications, energy grids, and transportation, among others.Subscribe to our free newslettersOur weekly newsletter Closing Arguments offers the latest about ongoing trials, major litigation and rulings in courthouses around the U.S. and the world, while the monthly Under the Lights dishes the legal dirt from Hollywood, sports, Big Tech and the arts.Additional Reads

Original Source

Read the full article at Courthousenews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.