CVE Tools

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The Hacker NewsBy The Hacker News

IncidentQScanQTFYQTRouter

Our summary

The U.S. Department of Justice has announced the seizure of infrastructure supporting the Chinese state-sponsored threat actor QTFY, specifically targeting the QScan and QTRouter botnets.

These platforms were utilized to breach critical U.S. institutions, including NASA, the Federal Reserve, and the Department of Energy, by exploiting vulnerabilities in vendor products such as Ivanti, Fortinet, Citrix, Microsoft, F5, Atlassian, Check Point, and BeyondTrust.

Notable exploits included zero-days like CVE-2024-8190 in Ivanti appliances and N-days such as CVE-2018-13379 in Fortinet SSL-VPN, allowing the group to maintain persistence and obfuscate traffic through compromised OpenWrt-based devices.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store