The United States government announced a significant victory in its ongoing battle against cyber threats by dismantling a Chinese-linked hacking platform. This platform, operated by the state-sponsored group QTFY, has been a menace to military and critical infrastructure systems in the US since 2018. Based in Nanjing, QTFY has provided hacking services that have facilitated numerous attacks on key sectors. The US authorities specifically targeted two of QTFY’s services: QScan, which identifies vulnerable Internet of Things devices, and QTRouter, a botnet used to mask malicious activities. By seizing domains integral to these services, the US Justice Department effectively rendered them inoperable.

These domains were essential for the platform's operations, including communication and authentication, making their seizure a critical blow to QTFY. The FBI's cybersecurity advisory reveals that QTFY has been actively developing and trading malware, as well as maintaining botnets. The group's wide range of targets included the defense industrial base, local governments, telecoms, and educational institutions. While some attacks against sensitive networks were unsuccessful, others, such as those on NASA and the Department of Energy, showed varying degrees of success.

The hackers exploited vulnerabilities in well-known products from companies like Microsoft, Citrix, and Fortinet. The FBI highlighted that QTFY is deeply involved in the exploit development community and collaborates with various Chinese cyber entities linked to espionage and intrusion activities. The disruption of QTFY's operations marks a significant step in protecting US infrastructure from foreign cyber threats.