For years, China's military and intelligence agencies, which carry out hacking campaigns against targets around the globe, have grown increasingly reliant on a vast web of proxy devices that enable and obfuscate their targeting. Now the FBI has named and disrupted one key network of those proxies—and in doing so, revealed just how extensively the hackers who used it reached into American government institutions and US critical infrastructure.
On Wednesday, the Department of Justice announced the takedown of two tools, known as QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY, which is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company. According to prosecutors and an FBI affidavit used to seize domains that those tools relied on, the company gave its customers access to botnets of hacked internet-of-things (IoT) devices and coopted commercial proxy services. The company's customers—allegedly including the Ministry of State Security and the People's Liberation Army—then used those proxy services as relay points to carry out hacking campaigns stretching back as early as 2018, according to the US government.
The DOJ says the hackers breached a staggering list of US victim agencies including NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself.
Nanjing Xinjiuwei Network Technology Company could not be immediately reached for comment.
The FBI's affidavit goes on to list types of US infrastructure and industries targeted via the proxy networks, too, including power companies, telecommunications providers, hospitals, financial institutions, and defense contractors—though it does not confirm which of the targeted entities were successfully breached or to what degree.
“The scale is really giant,” says Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, which worked with the FBI and DOJ on the takedown operation. In a blog post about the operation, Black Lotus Labs describes the Nanjing-based company as a kind of “quartermaster” for China's hacking operations, one of several private contractors that increasingly provide key tools and infrastructure to China's state-sponsored hackers.
“This is a very long lasting campaign,” Rouse says, “and this company and these people involved in it have very close ties to the highest levels of the People's Liberation Army.”
QScan, according to Lumen and the FBI, was designed to scan for vulnerabilities in IoT devices that could be hacked and added to botnets of infected devices that served as proxies. The company's QTRouter service allegedly managed customers’ access to that botnet network, as well as a network commercial proxies known as virtual private servers (VPS) that could simply be rented and used in hacking campaigns.
Over the last year, Rouse notes, the group had transitioned to hijacking virtual private network (VPN) services typically used by Chinese citizens to route around China's Great Firewall censorship system. Proxying Chinese hacking operations through those VPNs, Rouse says, created a layer of obfuscation that mixed malicious traffic with the benign traffic of Chinese users seeking to access the open internet. “It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were coopting,” Rouse says.
The FBI and Justice Department say that they've now disrupted the group's proxy infrastructure by seizing key domains hardcoded into QScan and QTRouter. Lumen, which serves as an internet backbone provider, says it also “null-routed” certain domains, rendering them inoperable—including the more recent system of coopting censorship-bypassing VPNs.
... continue reading