← CyberAdX Video · secureiot.house
FBI Cyber Division Disrupts China-Linked QTFY Botnet Targeting US Infrastructure
FBI Cyber Division head Brett Leatherman details the FBI and DOJ's disruption of a global botnet operated by Chinese state-sponsored group QTFY, which targeted US critical infrastructure for nearly a decade. The video is aimed at security professionals, critical infrastructure defenders and policymakers tracking nation-state cyber threats.
Transcript
I'm Brett Leatherman, head of the FBI Cyber Division. Today, the FBI and DOJ are announcing the disruption of a global botnet used by a Chinese state -sponsored group known as QTFY to target U .S. critical infrastructure. For nearly a decade, QTFY has exploited software vulnerabilities to launch cyber attacks against U .S. government agencies, power companies, telcos, and major hospitals. systems. QTFY operates within a complex network of hackers for hire and government clients in the People's Republic of China. Our investigation links the group to Nanjing Xinjouwei Network Technology, a company that sells stolen data and hacking services to Chinese military and intelligence agencies. Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers. and security cameras, infects thousands of them, and feeds them into a botnet or a network of machines secretly controlled by the adversary. These tools let QTFY hide the origin of their attacks. So instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries, potentially through systems just down the street from the victim's own network. Today, thanks to the work of FTPY, San Diego, the FBI Cyber Division teams, and our partners at DOJ, we shut these tools down. We seized multiple domains the platforms relied on for core functions like communication and authentication. Without those domains, the platforms were rendered inoperable. We're also issuing a joint cybersecurity advisory with our partners to help defenders protect their networks from this group. This action is just the latest technical operation against PRC. state -sponsored hacking. Last year, the FBI removed surveillance malware from thousands of U .S. systems. Before that, we disrupted botnets tied to Flax Typhoon and Volt Typhoon. In line with the new White House National Cyber Strategy, we are ramping up our efforts to shape adversary behavior and defend the homeland in cyberspace. But lasting deterrence depends on partnerships. Working with industry is how we deny the adversary either. gains, and raise the cost of every attack. To disrupt at scale, we have to coordinate at scale. So the mission belongs to all of us. Welcome to the fight.