US Justice Department Seizes QScan and QTRouter Domains, Alleging China State-Backed Hacking of Critical Networks
The US Justice Department, along with the FBI, has seized the domains related to QScan and QTRouter, alleging that they were used by a China state-backed hacking group to attack US government agencies and critical networks. The attribution is based on formal charges in government and court materials.
The US Justice Department and the Federal Bureau of Investigation (FBI) recently announced that they had seized the domains related to QScan and QTRouter, with court authorization. The US government alleged that these two platforms were developed and operated by a China-related hacking group, and were used to attack US government institutions, critical infrastructure, and other sensitive networks.
Court-Authorized Technical Enforcement Action
According to court materials released by the US Justice Department on August 26, a group called QTFY was hired by Nanjing Xingjiuwei Network Technology Co., Ltd. in Jiangsu, China, and provided hacking services to clients including China's Ministry of State Security and the People's Liberation Army.
It should be noted that these allegations belong to formal charges and attributions made by the US government in court materials, and are not conclusions of a criminal trial. The Beijing side has long denied US allegations of state-backed cyberattacks.
Infected Devices Become Infrastructure for Hidden Attack Sources
According to the Justice Department, QScan can scan and infect a large number of Internet of Things (IoT) devices, and then add these devices to a proxy network controlled by QTRouter. This allows attackers to make malicious traffic appear to come from outside China, or even from near the target network, thereby hiding the true source.
The Justice Department said that the targeted or breached institutions included NASA, the Federal Reserve, the Department of Energy, the Justice Department, the Department of Health and Human Services, the National Institutes of Health, and networks related to the US Senate.
Domain Seizure Disrupts Infrastructure
This action is not simply shutting down a website. The Justice Department said that the seized domains were written into the relevant malware for communication and authentication, so after the court-authorized seizure, the key functions of QScan and QTRouter were disrupted.
The US government has taken similar technical enforcement measures in recent years, targeting network infrastructure allegedly related to China, including PlugX, Flax Typhoon, and Volt Typhoon.
"Focus on China" believes that the news value of such cases lies not only in "where the hackers come from", but also in how the government uses court orders, malware analysis, and infrastructure control to form a verifiable chain of evidence. Attribution involving national security should especially adhere to this standard, and should not confuse government allegations, technical evidence, and judicial convictions.


文章讨论
已验证会员可围绕报道公开交流,并自行管理自己的内容。
正在检查会员登录状态…