FBI, Department of Justice Announce Disruption of Global Botnet – fbi.gov

A .gov website belongs to an official government organization in the United States.
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Share on X X.com Facebook Email Email
The FBI and the U.S. Department of Justice on August 26 announced the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure. In this video, FBI Cyber Division Assistant Director Brett Leatherman speaks to the significance of the disruption and discusses an associated Joint Cybersecurity Advisory that the Bureau and our partners issued to help defenders protect their networks from the group.
FBI Cyber Assistant Director Brett Leatherman: I’m Brett Leatherman, head of the FBI’s Cyber Division. 
Today, the FBI and DOJ [U.S. Department of Justice] are announcing the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure.  
For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems.  
QTFY operates within a complex network of hackers-for-hire and government clients in the People’s Republic of China. 
Our investigation links the group to Nanjing Xinjiuwei Network Technology—a company that sells stolen data and hacking services to Chinese military and intelligence agencies. 
Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet, or a network of machines secretly controlled by the adversary.   
These tools let QTFY hide the origin of their attacks.  
So, instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries—potentially through systems just down the street from the victim’s own network.  
Today—thanks to the work of FBI San Diego, the FBI Cyber Division teams, and our partners at DOJ—we shut these tools down. 
We seized multiple domains the platforms relied on for core functions like communication and authentication. 
Without those domains, the platforms were rendered inoperable. 
We’re also issuing a Joint Cybersecurity Advisory with our partners to help defenders protect their networks from this group. 
This action is just the latest technical operation against PRC state-sponsored hacking.  
Last year, the FBI removed surveillance malware from thousands of U.S. systems; before that, we disrupted botnets tied to Flax Typhoon and Volt Typhoon. 
In line with the new White House National Cyber Strategy, we are ramping up our efforts to shape adversary behavior and defend the homeland in cyberspace.  
But lasting deterrence depends on partnerships.  
Working with industry is how we deny the adversary easy gains and raise the cost of every attack.  
To disrupt at scale, we have to coordinate at scale. 
So the mission belongs to all of us. 
Welcome to the fight.  
Subscribe to our email newsletter for news on the FBI, sent out every week.
All FBI Email Updates All FBI Email Updates
935 Pennsylvania Ave NW
Washington DC 20535

source

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *