Chinese Hacking Attempts and U.S. Countermeasures

Chinese Hacking Attempts and U.S. Countermeasures

Overview of Chinese Cyber Attacks

Chinese hacking operations recently targeted crucial U.S. infrastructure. Before they could cause significant damage, the Department of Justice intervened, blocking these cyber infiltrations. An analysis of this national security threat was conducted by Bret Baier and the ‘Special Report’ All-Star Panel. They also discussed President Donald Trump’s 97% endorsement success rate in recent Republican primaries.

Details of Cyber Infiltration

Court records reveal that Chinese state-linked hackers stole sensitive data from over 300 organizations, including U.S. defense contractors, financial institutions, and universities. They breached three Energy Department laboratories, as well as the National Institutes of Health and an HHS agency. The FBI recently knocked their hacking platforms offline.

The QTFY Hacking Group

Operating through a China-based company, known as QTFY, the group sold hacking services to clients such as China’s Ministry of State Security and the People’s Liberation Army. Former PLA members worked for the company, leveraging military relationships to secure contracts for offensive cyber operations.

QTFY used mass internet scanning paired with compromised routers, cameras, and other internet-connected devices to disguise attack origins.

Methods and Technology Used

Federal officials reported that by routing malicious traffic through devices near the victim’s network, these hackers made attacks appear as local traffic, complicating detection and tracing.

The Justice Department and FBI seized three domains that powered QTFY’s main platforms: QScan and QTRouter. These platforms facilitated the identification of vulnerable systems and masked hackers’ identities.

The seizures severely disrupted QTFY’s operations by cutting off their primary means of communication.

Scale and Impact of QTFY’s Operations

Data shows that on a single day in 2024, QScan handled over 2 million scanning and penetration tasks, using more than 200 proof-of-concept exploits. Their focus was on finding vulnerable software and exposed services for exploitation.

Besides targeting NASA, QTFY attacked systems of the Justice Department, Federal Reserve, Senate, power companies, hospitals, telecommunications providers, defense contractors, and election infrastructure.

Challenges and Successes of U.S. Efforts

Attempts by QTFY to infiltrate organizations were not always successful. For instance, an attack on NASA in 2019 using a VPN vulnerability was thwarted as NASA had patched the flaw.

An advisory from the FBI, NSA, and Cyber National Mission Force revealed failed scans on Senate, hospital-system networks, and a U.S. election system.

However, successful attacks did occur. In May 2024, QTFY exploited a Check Point vulnerability and stole data from numerous organizations domestically and internationally.

Recent Breaches and Actions Taken

In later months, hackers capitalized on zero-day flaws in Ivanti Cloud Services Appliance software, gaining access to Department of Energy labs and other institutions, as per a government advisory.

Attorney General Todd Blanche stated emphatically that state-sponsored malicious hackers targeting U.S. critical infrastructure would be prosecuted.

Ongoing Countermeasures

The seizures are part of a series of FBI operations aimed at dismantling Chinese government-linked hacking infrastructure. In recent years, the FBI has disrupted various botnets utilized by groups like Volt Typhoon and Flax Typhoon, preventing further potential damage.

Last year, PlugX surveillance malware was removed from thousands of U.S. computers, protecting them from Mustang Panda, another China-linked hacking group.

Leave a Reply

Your email address will not be published. Required fields are marked *