NSA and FBI issue warning about Chinese hacking group QTFY

On August 26, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF) in releasing a joint cybersecurity advisory titled, “China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems.”

This guidance alerts organizations about China-linked cyber threat actors using the acronyms QTFY, QT and QTCYBER who have developed malicious distributed platforms to compromise the networks of U.S. and foreign organizations.

Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet and ultimately targeted critical systems in the U.S. Organizations from multiple sectors have been targeted including the Defense Industrial Base, telecommunications, local government and higher education, among others.

QTFY actors have developed branded products that work in conjunction with each other and include the vulnerability scanning and exploitation platform “QScan” to conduct reconnaissance, exploit vulnerable Internet of Things (IoT) devices and identify vulnerabilities in networks, an obfuscation network named “QTRouter” to blend in with legitimate users, and at least three major platforms that can manage botnets of compromised IoT devices and include them as obfuscation network nodes (“Proxy Platform Management,” “Proxy Pool Management System” and “QTBotnet”).

QTFY threat actors exploit zero-day and N-day vulnerabilities to gain initial access to victim networks and obtain legitimate credentials from compromised systems to maintain persistence and are active in the exploit development community via freelance hacker networks and malicious cyber contracting and subcontracting marketplaces.

The authoring agencies recommend organizations implement the following mitigations to improve overall cybersecurity posture based on QTFY activity:

  • Apply the latest software and firmware updates to your organization’s devices.
  • Regularly audit your organization’s webpages and internet-facing apps to protect operational information from unintended disclosure.
  • Isolate critical systems from edge devices.
  • Hunt for the provided indicators of compromise

 

Source: NSA

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.