Feds in San Diego seize domains to block China from hacking
National News
Audio By Carbonatix
5:30 PM on Monday, August 31
(The Center Square) – Federal law enforcement has seized core infrastructure reportedly used by a Chinese state-sponsored cyber platform to target high-profile U.S. government entities and critical infrastructure in a campaign dating back to 2018.
Authorities said the hacking targets varied from NASA to the Federal Reserve.
The U.S. Department of Justice and the FBI last week announced the court-authorized domain seizures targeting QScan and QTRouter, two cyber platforms that investigators said have ties to a Chinese group known as QTFY.
Officials announcing the seizures included U.S. Attorney Adam Gordon for the Southern District of California, as well as Special Agent in Charge Mark Remily of the FBI San Diego Field Office.
Authorities said QTFY worked through Nanjing Xinjiuwei Network Technology Co. to provide hacking services to Chinese intelligence and military arms.
Among QTFY's targets were NASA, the Federal Reserve, and the U.S. departments of Energy, Justice, and Health and Human Services, as well as the U.S. Senate.
According to court filings, the platforms infected thousands of devices worldwide to construct an obfuscation network that masked attack origins. Federal agents reportedly neutralized both tools by seizing hard-coded domains essential for the malware's communication.
U.S. Attorney General Todd Blanche said this sends a message to hackers worldwide.
"State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said Blanche in a press release. “We are here to ensure security for the American people and will use every tool we have to keep that promise."
Remily said the FBI remains relentless in its efforts to counter nation-state cyber actors, taking decisive action against those threatening the United States and its critical infrastructure.
“Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries,” said Remily.
Bryce G. Poole, senior legal fellow with the Edwin Meese III Institute for the Rule of Law at Advancing American Freedom, applauded law enforcement for its actions.
Poole said this is exactly how the rule of law is supposed to work against state-sponsored cyber threats.
“The Department of Justice went to a federal court. They got a lawful court order, court-authorized search warrants, and they disabled the tools, and they did this all through the court system,” Poole said during a phone interview with The Center Square. “They were able to do what they needed to do to protect our national security interests, and they did it through the court system.”
Pointing to the various targets, Poole said this is not just a California problem.
“And it never was a local California problem because you're talking about Chinese state-sponsored Chinese hackers sponsored by the Chinese PRC,” said Poole, referring to the People's Republic of China. “Even if we set that aside and you would just say, ‘Hey, these were local hackers in Southern California,’ well, the targets were not local, and so this was aimed at the core machinery of the American government.”
Ali Holcomb, a national security fellow at the organization Advancing American Freedom and former spokesperson for the national security division at DOJ during the first Trump administration, called for the current administration to be tough on China.
“The CCP [Chinese Communist Party] is our growing adversary and is weaponizing technological advances to target the U.S., be it AI, social media, or hacking platforms, like in this case,” Holcomb told The Center Square in an email. “The Trump administration should follow the steps of their first administration and reinstitute the China Initiative, to continue to highlight the growing threat from the CCP."