Chinese Hackers Broke Into NASA, Federal Reserve, DOJ & Senate: FBI Announces
The United States Department of Justice has on Wednesday announced US authorities thwarted a major state-sponsored hack which saw a temporary intrusion into NASA, the Federal Reserve, Senate, the DOJ, Department of Energy, and the Department of Health and Human services, along with four unnamed companies in the US and South Korea.
"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," said FBI Director Kash Patel.
"These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down," he added.

Domains utilized by two hacking platforms identified as "QScan" and "QTRouter" were seized by the DOJ in the large scale counter-cyberespionage operation.
Describing a pervasive botnet which was ultimately believed to be backed by Chinese state actors, The Wall Street Journal details that the "goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace, federal officials say."
"The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the Federal Bureau of Investigation’s top cyber official," WSJ continues.
As for the specific allegation that this had state backing, the DOJ press release states:
People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.
The DOJ announcement additionally outlines efforts at concealment and 'plausible deniability' in the following:
QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an “obfuscation network” – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.
Neither Beijing's foreign ministry nor the Chinese embassy in Washington have officially responded to the allegations, and as has been the pattern in the past is likely to reject the US charge altogether.
Earlier this year Google was among those warning of imminent stepped-up Chinese and Russian targeting of US defense companies.
Google's prior report seemed to preview some of the techniques on display in this latest hack. The report cited observations of "more China-nexus cyber espionage missions directly targeting defense and aerospace industry than from any other state-sponsored actors over the last two years."
"But the hallmark of many operations has been their exploitation of edge devices to gain initial access," it said, referring to hardware components positioned at the edge of a network. "We have also observed China-nexus threat groups leverage ORB networks for reconnaissance against defense industrial targets, which complicates detection and attribution."
