China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems


The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. The cyber actors’ products have enabled hackers to obfuscate their location and target systems in critical infrastructure sectors including defense industrial base (DIB), communications, government, and higher education. This advisory provides details on the actors’ activities; tactics, techniques, and procedures (TTPs); infrastructure details; and indicators of compromise (IOCs). The information is derived from incident response and investigative techniques.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Atlanta, hit by ransomware attack, also fell victim to leaked NSA exploits

    March 27, 2018

    It’s been almost a week since the City of Atlanta was hit by a ransomware attack, which encrypted city data and led to the shutdown of some services. Mayor Keisha Lance Bottoms said in a press conference Monday that the city’s government is working on recovering the network after ransom notes appeared on computer displays on Thursday afternoon. ...

  • Old banking Trojan TrickBot has been taught new tricks

    March 22, 2018

    The TrickBot Trojan has been upgraded with new modules to make detection, and defense, more difficult. First discovered in 2016, TrickBot is a financial Trojan which targets the customers of major banks. The Trojan is most commonly connected to phishing campaigns which trick users into entering their credentials into phishing and fraudulent banking websites, designed to appear as legitimate ...

  • US slaps new sanctions on Russia over NotPetya cyberattack, election meddling

    March 15, 2018

    The White House has introduced a new round of sanctions on Russia, accusing the government of launching “the most destructive and costly cyberattack in history.” In a statement, the US Treasury said it has targeted 19 individuals and five entities for their parts in conducting “destabilizing activities,” including interfering with the US elections in 2016 to their ...

  • Cyberattacks Put Russian Fingers on the Switch at Power Plants, U.S. Says

    March 15, 2018

    The Trump administration accused Russia on Thursday of engineering a series of cyberattacks that targeted American and European nuclear power plants and water and electric systems, and could have sabotaged or shut power plants off at will. United States officials and private security firms saw the attacks as a signal by Moscow that it could disrupt ...

  • US special counsel indicts 13 members of Russia’s election meddling troll farm

    February 16, 2018

    Special Counsel Robert Mueller’s office said Friday that a grand jury has indicted 13 Russian nationals and three Russian entities accused of violating federal laws in order to interfere with US elections and political processes during the 2016 presidential race. The indictment says that the defendants, by early to mid-2016, were “supporting the presidential campaign of then-candidate Donald ...

  • Cyber Espionage Group Targets Asian Countries With Bitcoin Mining Malware

    February 7, 2018

    Security researchers have discovered a custom-built piece of malware that’s wreaking havoc in Asia for past several months and is capable of performing nasty tasks, like password stealing, bitcoin mining, and providing hackers complete remote access to compromised systems. Dubbed Operation PZChao, the attack campaign discovered by the security researchers at Bitdefender have been targeting organizations in the government, ...