Federal authorities disclosed a long-running Chinese state-sponsored espionage campaign by QTFY that has targeted U.S. critical infrastructure and multiple federal agencies since 2018. The operation used a botnet, scanning tools, and exploited vulnerabilities in products from Ivanti, Fortinet, Citrix, Microsoft, F5, and others to infiltrate sensitive networks. #QTFY #QScan #QTRouter #Ivanti #PlugX
Keypoints
- QTFY is a Chinese state-sponsored group that has operated for more than eight years.
- The group targeted U.S. agencies including DOE, DOJ, HHS, the Federal Reserve, NASA, and NIH.
- Officials seized three domains linked to QScan and QTRouter to disrupt the operation.
- QTFY used a large-scale scanning and exploit platform with more than 200 proof-of-concept exploits.
- The campaign exploited vulnerabilities in products from Ivanti, Fortinet, Citrix, Microsoft, F5, and others.
Read More: https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/