Washington—A cyber espionage operation linked by US authorities to China has reached some of the most sensitive networks of the US government, including those of the Department of Justice, the Federal Reserve, the Senate, and other federal agencies.
The case came to light this Wednesday after the Department
of Justice and the FBI announced the dismantling of two platforms used by the
group identified as QTFY to carry out cyberattacks and conceal their true
origin.
According to court documents, the tools known as QScan and
QTRouter were allegedly used since at least 2018 to compromise
internet-connected devices and subsequently use them as intermediaries in
attacks against various targets.
Among the institutions named by US authorities are NASA, the
Federal Reserve, the Department of Justice, the Department of Energy, the
Department of Health and Human Services, the National Institutes of Health, and
the Senate.
The US government attributes the operation to the QTFY
group, linked to the Chinese company Nanjing Xinjiuwei Network Technology
Company, which it connects to clients of the Ministry of State Security and the
People's Liberation Army of China.
One of the key aspects of the operation was precisely to
make it difficult for investigators to identify the origin of the attacks.
QScan allowed the infection of devices worldwide, while QTRouter was used to
conceal the true origin of the connections.
