US disrupts Chinese cyber espionage network used to hide attacks

 

US disrupts Chinese cyber espionage network used to hide attacks

The US Justice Department and the FBI have disrupted infrastructure linked to QTFY, a China-linked threat actor that provided reconnaissance, proxy management and traffic-routing services for espionage operations against US organizations.

According to the DOJ, QTFY operated two hacking platforms called QScan and QTRouter. QScan was used for reconnaissance and vulnerability scanning, collecting information such as open ports, application banners, operating system fingerprints and network configuration data. QTRouter helped attackers connect to proxy infrastructure and create routes that concealed their real locations.

Researchers at Lumen Technologies identified several parts of the system, including Fast Labyrinth, an encrypted relay network, and QTProxy, a management tool used to select proxy relays and configure traffic routes. The infrastructure formed an Operational Relay Box-style network, allowing attackers to send malicious traffic via compromised or commercially operated devices.

QTFY used domains including qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com to operate parts of the platform. The FBI has seized the domains, which now display a law enforcement notice. Lumen also disrupted known infrastructure by null-routing traffic to identified QTFY systems.

The group reportedly used the infrastructure against NASA, the Federal Reserve, the US Senate and several government agencies, as well as military, defense, healthcare, financial, energy and research organizations.

The operation used commercial proxy nodes instead of compromised devices. QTFY bought access to selected nodes operated by a Chinese proxy service, which were then used to create Fast Labyrinth and automatically rotate the network's exit points.

Lumen said connections between organizations identified during QScan reconnaissance and later activity through Fast Labyrinth provide evidence that the infrastructure was used for follow-up exploitation, lateral movement, persistent access or data theft.

Researchers warn that blocking known IP addresses and domains alone will have limited impact because the operators can use rotating commercial proxies to swiftly change the routing infrastructure.

Back to the list