A Chinese government-backed hacking group has spent years attacking hundreds of American institutions, including some of the country's most sensitive federal agencies. The Justice Department and FBI announced the findings Wednesday, identifying the group as QTFY and describing a campaign stretching back to 2018 that targeted government agencies, hospitals, telecommunications providers, power companies, and defense contractors.
According to ABC News, the targets included NASA, the National Institutes of Health, the Department of Health and Human Services, the Justice Department, the Department of Energy, the U.S. Senate, and the Federal Reserve. The charges were outlined in an affidavit unsealed Wednesday in federal court in California.
QTFY includes former members of China's military. Prosecutors said the group operated through a Chinese company called Nanjing Xinjiuwei Network Technology Company. As part of the enforcement action, prosecutors successfully seized three internet domains affiliated with that company.
Court documents stated that in September 2024, QTFY hackers conducted intrusions at three Energy Department laboratories, NIH, an HHS agency, and an unnamed U.S. security device manufacturer. The group also allegedly attempted a hack against NASA in 2019, though documents do not indicate that effort succeeded.
The court filings do not specify the full scale of damage across all the agencies listed, and the level of success in infiltrating some specific networks was not detailed.
"Today's announcement demonstrates the Justice Department's steadfast commitment to going on the offensive against cyber threats to the national security," said Assistant Attorney General for National Security John Eisenberg. "These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure."
The FBI and the National Security Agency released an advisory with indicators of QTFY activity. Lumen Technologies' threat intelligence group, Black Lotus Labs, also published a description of the group's tactics to help organizations protect themselves from future attacks.
Javed Ali, a former senior director for counterterrorism at the National Security Council, said China's cyber operations against the United States remain relentless, adding that China has been conducting these operations for roughly 20 years using multiple targets and multiple attack methods.
