The FBI and Justice Department announced on August 26 that they disrupted QTFY, a China-linked hacking group that has targeted hospitals and health systems along with government services, communications, energy, information technology, and water and wastewater systems.
Federal agencies seized domains tied to two of the group’s tools, QScan and QTRouter, making them inoperable. QScan infected internet-connected devices worldwide to build a botnet, while QTRouter routed the group’s attacks through those devices, commercial proxies, and rented servers to hide the origin of the traffic. Court documents tie QTFY, active since 2018, to a Nanjing-based company and to customers including China’s Ministry of State Security and the People’s Liberation Army.
Targets listed by investigators include NASA, the Federal Reserve, the Energy and Justice departments, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The FBI and NSA published a joint advisory with indicators of compromise, joined by the Cyber National Mission Force.
“This serious China-based cyber threat once again demonstrates that the line between foreign criminal hacking groups, their infrastructure and hostile intelligence services is becoming increasingly blurred,” said John Riggi, AHA national advisor for cybersecurity and risk.
Hospital security teams should review the advisory’s indicators, inventory internet-exposed devices, and patch known vulnerabilities in network equipment.