DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
DoJ updates statement, now says agencies were targets, not victims of Chinese threat actors.
Intelligence analysis by Qwen 2.5 (3B)

U.S. agencies previously claimed to be victims of Chinese hacking. DoJ now says they were targets, not victims.
The U.S. government says they were targeted by hackers from China, not attacked by them. This is a change from what they said before.
Analysis
{"heading_1":"QTFY and Its Affiliates","paragraph_1":"QTFY is a state-sponsored group linked to the People's Republic of China (PRC). It works for a private Chinese company, Nanjing Xinjiuwei Network Technology Co, which receives payments from the Ministry of State Security (MSS).","paragraph_2":"QTFY has been active since 2018 and has targeted U.S. federal government networks, hospitals, telecom operators, power companies, financial institutions, and defense contractors.","paragraph_3":"The threat actor uses QScan and QTRouter, two core products in its arsenal, for reconnaissance, proxy management, and operational routing capabilities.","paragraph_4":"In one instance, QTFY attempted to breach NASA using CVE-2019-11510, a critical vulnerability in Pulse Secure VPN.","paragraph_5":"The FBI has disrupted QTFY's domains, neutralizing the malware's functions.","paragraph_6":"QTFY sells access to QScan and QTRouter to other actors to identify and exploit vulnerable IoT devices, creating a decentralized botnet of infected devices and leased VPSs."}
Key points
- DoJ updates its statement to clarify that U.S. agencies were targets, not victims, of Chinese hacking.
- QTFY is a state-sponsored group linked to China, active since 2018.
- The threat actor uses QScan and QTRouter for reconnaissance and operational routing.
The update could lead to better coordination and response from U.S. agencies to cyber threats.
The change in wording could lead to confusion or misinterpretation of the threat level.



