UPDATE After publication, the US Justice Department walked back its earlier claims that multiple US government agencies were hacked by Beijing's cyberspies. In an updated press release, the feds removed "victims," and now says NASA, the Federal Reserve, departments of Energy, Justice, and Health and Human Services, along with the National Institutes of Health, and the US Senate were "targets."
The FBI on Wednesday said it disrupted a botnet and seized two platforms that Chinese-government cyberoperatives used to hack NASA, the US Senate, the Department of Energy, and several other government agencies and critical networks.
The Federal Reserve, Department of Justice, Department of Health and Human Services, and the National Institutes of Health were also among those victimized by the two now-seized hacking tools: a vulnerability scanning and exploitation malware named QScan, and an obfuscation network named QTRouter.
The FBI says a People's Republic (PRC) of China-backed group called QTFY created and operated the two platforms, plus botnets of compromised IoT devices. The Bureau says QTFY's hackers work for a private PRC company called Nanjing Xinjiuwei.
[...] QScan scans and automatically infects thousands of IoT devices worldwide, and then adds them to the QTRouter network of QTFY-controlled devices.
The QTRouter botnet – consisting of these compromised IoT devices, plus commercial proxy service devices, and leased virtual private servers – then serves as an obfuscation network, allowing QTFY and other criminals who pay for the service to conceal the origin of their digital intrusion activities, making these communications appear to originate from local computers.
On Monday, a US federal court granted seizure warrants for three domains linked to QTFY: qtproxy.xyz, qt-proxy.org, and qt-team.com. All three domains were hardcoded into both the QScan and QTRouter malware, and the court-authorized seizures made both hacking services inoperable, the Justice Department said.
The hacking services and malware have been in use since at least 2018, and as recently as this year when QTFY infrastructure compromised the US Senate, according to court documents.
[...] This latest disruption follows a series of court-ordered seizures intended to hamstring China's hacking activities over the last few years. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 US computers that had been infected by the PRC-sponsored group Mustang Panda.
A year earlier, in 2024, China's Flax Typhoon burned down their own botnet consisting of hundreds of thousands of infected internet-of-things devices when confronted by the feds. And in late 2023, the FBI disrupted a botnet used by yet another Chinese government attack crew, Volt Typhoon, to attack US and foreign critical infrastructure.
In June, however, Lumen's Black Lotus Labs reported a "significant resurgence" of a botnet linked to Volt Typhoon, with this cluster of injected machines surging to 1,500 compromised routers and IoT devices.
(Score: 3, Insightful) by janrinok on Wednesday September 02, @07:06AM (1 child)
If they don't contain anything of any significance why go to all the trouble to hide them, to censor them, to claim that they don't exist? Why do you seem to think that they are unimportant?
They might contain information that is embarrassing to many people - let the world see them and bring those who might be named to face public account, whoever and wherever they may be.
(Score: 2) by DadaDoofy on Wednesday September 02, @10:46PM
"If they don't contain anything of any significance why go to all the trouble to hide them, to censor them, to claim that they don't exist?"
Precisely! And I wholeheartedly agree. It makes absolutely no sense whatsoever that while the files were under control of Biden's DOJ, they would have gone "to all the trouble to hide them, to censor them, to claim that they don't exist" unless there was nothing whatsoever that would incriminate Trump in them.
I'm quite sure the democrats wouldn't have needed to twist and turn their way through their novel, unprecedented legal manipulations to turn a misdemeanor bookkeeping error into 44 felony convictions if there had been even the slightest hint Trump was acting inappropriately with minors in those files.