Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the Nuances of State-Sponsored Cyber Attacks: The U.S. Department of Justice's Correction on Chinese Hacking Claims


The U.S. Department of Justice has corrected its earlier statement regarding Chinese hacking claims, indicating that several U.S. agencies were targets rather than victims of Chinese cyber espionage. The correction highlights the need for a more nuanced understanding of state-sponsored hacking and the importance of effective law enforcement agencies in disrupting these threats.

  • The US Department of Justice (DoJ) has corrected its earlier statement regarding Chinese hacking claims, indicating that several US agencies were targets, not victims, of Chinese cyber espionage.
  • The DoJ initially named several US agencies as victims, but later clarified that they were actually targets of Chinese hacking efforts.
  • The corrected statement aims to ensure that the government's allegations are accurately reflected in the affidavit in support of the domain seizures.
  • The threat actor, QTFY, has targeted a broad range of organizations, including hospitals, telecom operators, and defense contractors, since 2018.
  • The US Federal Bureau of Investigation (FBI) has disrupted the domains connected to QScan and QTRouter, effectively neutralizing the malware's functions.
  • The correction highlights the need for a more nuanced understanding of state-sponsored hacking and the need for effective law enforcement agencies to disrupt these threats.
  • QTFY sells access to QScan and QTRouter to other actors, allowing them to identify and exploit vulnerable IoT devices.



  • The realm of cybersecurity has long been marred by the specter of state-sponsored hacking, with nations employing their cyber warfare arsenals to infiltrate and pilfer the digital treasures of other nations. In a recent development that has shed new light on the intricacies of this nefarious phenomenon, the U.S. Department of Justice (DoJ) has corrected its earlier statement regarding Chinese hacking claims. The correction, which has significant implications for the nation's cybersecurity landscape, indicates that several U.S. agencies were, in fact, targets rather than victims of Chinese cyber espionage.

    The initial statement, issued by the DoJ last week, had alleged that the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were among the victims of "computer intrusion activity" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China (PRC). However, in its revised statement, the DoJ has clarified that these agencies were, in reality, among the targets of QTFY's hacking efforts.

    According to the DoJ, the corrected statement aims to ensure that the government's allegations in the affidavit in support of the domain seizures are accurately reflected. The affidavit, which was filed in connection with the domain seizures, described QTFY as a technical quartermaster that has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. The threat actor is believed to have been active since 2018 and has targeted a broad range of organizations, including hospitals, telecom operators, power companies, financial institutions, and defense contractors.

    One notable aspect of the corrected statement is its emphasis on the notion that while the activity may have targeted a broad range of organizations, only some of them were actually compromised. This distinction is significant, as it highlights the nuances of state-sponsored hacking and the need for a more nuanced understanding of the complex cyber threat landscape.

    The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter, effectively neutralizing the malware's functions. This development has significant implications for the nation's cybersecurity landscape, as it demonstrates the effectiveness of law enforcement agencies in disrupting state-sponsored cyber threats.

    In addition to the corrected statement, the DoJ has also revealed that Lumen Black Lotus Labs has discovered that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations. This development highlights the growing sophistication of state-sponsored hacking groups and the need for a more effective response to these threats.

    Furthermore, the DoJ has revealed that QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter. The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws, which underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity.

    The correction by the DoJ has significant implications for the nation's cybersecurity landscape, as it highlights the need for a more nuanced understanding of state-sponsored hacking and the need for effective law enforcement agencies to disrupt these threats. As the cyber threat landscape continues to evolve, it is essential that policymakers, law enforcement agencies, and the private sector work together to develop a comprehensive strategy for addressing these threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-Nuances-of-State-Sponsored-Cyber-Attacks-The-US-Department-of-Justices-Correction-on-Chinese-Hacking-Claims-ehn.shtml

  • https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html

  • https://www.yahoo.com/news/articles/us-officials-backpedal-claims-government-193539966.html


  • Published: Mon Aug 31 04:22:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us