Officials disrupt Chinese espionage operation that hit multiple federal agencies

Officials disrupt Chinese espionage operation that hit multiple federal agencies
Federal authorities disclosed a long-running Chinese state-sponsored espionage campaign by QTFY that has targeted U.S. critical infrastructure and multiple federal agencies since 2018. The operation used a botnet, scanning tools, and exploited vulnerabilities in products from Ivanti, Fortinet, Citrix, Microsoft, F5, and others to infiltrate sensitive networks. #QTFY #QScan #QTRouter #Ivanti #PlugX

Keypoints

  • QTFY is a Chinese state-sponsored group that has operated for more than eight years.
  • The group targeted U.S. agencies including DOE, DOJ, HHS, the Federal Reserve, NASA, and NIH.
  • Officials seized three domains linked to QScan and QTRouter to disrupt the operation.
  • QTFY used a large-scale scanning and exploit platform with more than 200 proof-of-concept exploits.
  • The campaign exploited vulnerabilities in products from Ivanti, Fortinet, Citrix, Microsoft, F5, and others.

Read More: https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/