Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve
ID: ff7fa023-8e13-5c34-83f7-5a3d08b80adc
STIX ID: report--ff7fa023-8e13-5c34-83f7-5a3d08b80adc
Feed Name: Security Boulevard
U.S. authorities disrupted two hacking platforms — QScan (device-scanning and compromise) and QTRouter (proxying through compromised devices and VPSs) — allegedly run by China-linked QTFY and employed by Nanjing Xinjiuwei; the infrastructure enabled location-camouflaged operations that targeted high-value U.S. government agencies, critical infrastructure, defense contractors and financial institutions across a multi-year campaign spanning at least 2018–2026, with reported intrusions and data theft in 2024 and scanning/attempted intrusions as recently as 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
