Chinese Hackers Broke Into NASA, Federal Reserve, DOJ & Senate: FBI Announces

Original article here


The United States Department of Justice has on Wednesday announced US authorities thwarted a major state-sponsored hack which saw a temporary intrusion into NASA, the Federal Reserve, Senate, the DOJ, Department of Energy, and the Department of Health and Human services, along with four unnamed companies in the US and South Korea.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel.

“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down,” he added.

via Reuters

Domains utilized by two hacking platforms identified as “QScan” and “QTRouter” were seized by the DOJ in the large scale counter-cyberespionage operation.

Describing a pervasive botnet which was ultimately believed to be backed by Chinese state actors, The Wall Street Journal details that the “goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace, federal officials say.”

“The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the Federal Bureau of Investigation’s top cyber official,” WSJ continues.

As for the specific allegation that this had state backing, the DOJ press release states:

People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.

The DOJ announcement additionally outlines efforts at concealment and ‘plausible deniability’ in the following:

QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an “obfuscation network” – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable. 

Neither Beijing’s foreign ministry nor the Chinese embassy in Washington have officially responded to the allegations, and as has been the pattern in the past is likely to reject the US charge altogether.

Earlier this year Google was among those warning of imminent stepped-up Chinese and Russian targeting of US defense companies.

Google’s prior report seemed to preview some of the techniques on display in this latest hack. The report cited observations of “more China-nexus cyber espionage missions directly targeting defense and aerospace industry than from any other state-sponsored actors over the last two years.”

US imposes new sanctions on China by September 30?
Yes 21% · No 80%
View full market & trade on Polymarket

“But the hallmark of many operations has been their exploitation of edge devices to gain initial access,” it said, referring to hardware components positioned at the edge of a network. “We have also observed China-nexus threat groups leverage ORB networks for reconnaissance against defense industrial targets, which complicates detection and attribution.”

Share This Story, Choose Your Platform!

About the Author: Patriotman

Patriotman currently ekes out a survivalist lifestyle in a suburban northeastern state as best as he can. He has varied experience in political science, public policy, biological sciences, and higher education. Proudly Catholic and an Eagle Scout, he has no military experience and thus offers a relatable perspective for the average suburban prepper who is preparing for troubled times on the horizon with less than ideal teams and in less than ideal locations. Brushbeater Store Page: http://bit.ly/BrushbeaterStore

Leave a Reply

Howitzer Clothing – Code AP15 for 15% OFF

CIVIL DEFENSE MANUAL – Only $56.29 This Month!

GUNS N GEAR

Categories

Archives