China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems


The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. The cyber actors’ products have enabled hackers to obfuscate their location and target systems in critical infrastructure sectors including defense industrial base (DIB), communications, government, and higher education. This advisory provides details on the actors’ activities; tactics, techniques, and procedures (TTPs); infrastructure details; and indicators of compromise (IOCs). The information is derived from incident response and investigative techniques.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Twitter, Meta kill hundreds of pro-Western troll accounts

    August 25, 2022

    Well known for an abundance of anti-western troll accounts and propaganda, Twitter and Meta are reporting that they’ve taken down nearly 200 accounts that, for the past five years, have been amplifying pro-Western messages in the Middle East and Central Asia. Stanford Internet Observatory (SIO) and Graphika, a social media analytics company, have published a report ...

  • CISA: Preparing Critical Infrastructure for Post-Quantum Cryptography

    August 24, 2022

    Nation-states and private companies are actively pursuing the capabilities of quantum computers. Quantum computing opens up exciting new possibilities; however, the consequences of this new technology include threats to the current cryptographic standards. These standards ensure data confidentiality and integrity and support key elements of network security. While quantum computing technology capable of breaking public ...

  • CISA Releases Cybersecurity Toolkit to Protect U.S. Elections

    August 10, 2022

    CISA—through the Joint Cyber Defense Collaborative (JCDC)—has released a toolkit of free cybersecurity resources for the election community. The toolkit aims to help state and local government officials, election officials, and vendors enhance the cybersecurity and cyber resilience of U.S. election infrastructure. The toolkit resources, which come from CISA, JCDC members, and others across the cybersecurity ...

  • Former Twitter worker convicted of spying for Saudi Arabia

    August 10, 2022

    A former Twitter employee has been convicted of failing to register as an agent for Saudi Arabia and other charges after accessing private data on users critical of the kingdom’s government in a spy case that spanned from Silicon Valley to the Middle East. Ahmad Abouammo, a U.S. citizen and former media partnership manager for Twitter’s ...

  • Iowa: 3 injured in Google data center explosion

    August 9, 2022

    An explosion at Google’s date center in the US state of Iowa left three people injured on late Monday, local media reported. Three electricians were critically injured with significant burns after an “electrical incident,” police and Google told SFGATE news website. Google has 14 data centers in the US and 23 in total around the world, according ...

  • Website of Taiwan’s presidential office receives overseas cyber attack

    August 2, 2022

    The website of Taiwan’s presidential office received an overseas cyber attack on Tuesday and was at one point malfunctioning, a source briefed on the matter said. The website was shortly brought back online, the source told Reuters. U.S. House of Representatives Speaker Nancy Pelosi was expected to arrive in Taipei later on Tuesday, people briefed on ...