Cyberattacks often originate from unexpected sources such as old routers and forgotten security cameras. Hackers exploit these vulnerable devices to obscure the true origin of attacks. This tactic played a role in a series of China-linked cyberattacks targeting U.S. networks.
Notable Targets of the Cyberattacks
On August 26, the Justice Department and FBI confirmed intrusion attempts against NASA, the Federal Reserve, the Justice Department, and the U.S. Senate since 2018. Other targets included the Department of Energy, Health and Human Services, and National Institutes of Health.
Additionally, four unnamed companies in the U.S. and South Korea were reportedly targeted. The Justice Department attributes these attacks to a Chinese group called QTFY, using tools known as QScan and QTRouter.
How the Hacking Operation Worked
QScan identified vulnerable systems and infected IoT devices globally. These devices were then incorporated into QTRouter, an obfuscation network, which concealed the true origin of attacks. This network included compromised IoT devices, commercial proxy devices, and leased virtual private servers.
By routing communications through this infrastructure, malicious activity appeared to originate outside China, complicating tracking efforts by security teams. Such tactics underline the importance of securing all connected devices.
Federal Response to the Cyber Operation
The Justice Department obtained court authorization to seize domains used by QScan and QTRouter, disrupting the operation. These domains were integral for communication and authentication within the malware. Taking control of them rendered the hacking tools inoperative.
Black Lotus Labs noted that targeting shared infrastructure can disrupt multiple cyber operations simultaneously. The labs shared intelligence with government agencies, helping to mitigate emerging risks by blocking known threat infrastructure.
Protecting Your Connected Devices
While you can’t stop nation-state hacking operations alone, safeguarding your devices is crucial. Here are practical steps to protect your connected devices:
- Update your router firmware: Regularly check for updates through your router’s app or administration page.
- Replace outdated routers: Ensure your router receives regular security updates. Replace any that are no longer supported.
- Change default passwords: Use strong, unique passwords for the router’s administrator and Wi-Fi networks.
- Enable strong encryption: Opt for WPA3 encryption in your router’s security settings when available.
- Disable unnecessary features: Turn off remote administration, WPS, and UPnP if not in use.
- Use a separate network for smart devices: Place IoT devices on a guest or dedicated network.
- Keep all devices updated: Regularly update firmware and software for security.
- Stay vigilant: Watch for unusual network behavior or unfamiliar connected devices.
Informed vigilance can prevent your household tech from becoming part of a larger attacker’s network. Take these simple steps to bolster the security of your connected devices and protect sensitive information.

Leave a Reply