THE US government has successfully disrupted a Chinese hacking platform and botnet known as QTFY, which has been targeting military and critical infrastructure systems since 2018. The disruption included seizing domains used by QTFY's hacking services, specifically QScan and QTRouter. QScan identifies vulnerable IoT devices, while QTRouter helps hide malicious activities.
The FBI's advisory revealed that QTFY has attacked various sectors, including defense, local government, and education, often exploiting vulnerabilities in major software. Some attacks were successful against significant US entities, demonstrating the persistent threat posed by QTFY and its connections to other cyberespionage groups.