United States seizes Internet domain names suspected of being used by Chinese spies
The American Department of Justice and the FBI announced on Wednesday August 26 the seizure of domain names on the Internet suspected of being used by Chinese agents to conceal the origin of their cyberattacks. In a press release, the ministry specified that it had seized these domain names in order to“denying malicious cyber actors access to two hacking platforms, known as QScan and QTRouter, used to target vital US infrastructure and other sensitive networks.”
These platforms were created by a group called QTFY, whose cyberattacks notably targeted NASA, the American space agency, the American ministries of energy, justice and health, as well as the Senate, according to the text.
This entry is “the latest in a series of technical operations to dismantle cyberpiracy activities sponsored by the People’s Republic of China whatever their nature”according to the American Minister of Justice, Todd Blanche, quoted in the press release.
Confidential information extracted from American officials
“These instruments were used by Chinese cyber actors to conceal the origin of their attacks”explained FBI Director Kash Patel. In particular, they allowed them to hide the fact that these computer intrusions came from China, according to the press release. QTFY’s clients include China’s Ministry of State Security and the Chinese People’s Liberation Army, the ministry said.
In June, American authorities had already announced the seizure of thirteen domain names suspected of being used by suspected Chinese agents to extract confidential information from American officials benefiting from security accreditations.
The Five Eyes intelligence alliance, which includes the United States, the United Kingdom, Canada, Australia and New Zealand, had previously warned of a campaign by Chinese intelligence agents posing as recruiters for consultancies or think tanks.