CSIDB logo
Incident

National Institutes of Health

Incident posture

Attack window
May 2024
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:52

Linked entities

Victim
National Institutes of Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A China-linked hacking group known as QTFY exploited zero-day flaws in Ivanti Cloud Services Appliance software to breach three Department of Energy national laboratories, the National Institutes of Health, and the Health Resources and Services Administration, according to a federal advisory. The attacks occurred alongside broader intrusions that compromised more than 300 organizations, including U.S. defense contractors, financial institutions, universities, power companies, hospitals, telecommunications providers, and election infrastructure. QTFY operated through a China-based company that sold hacking services to China's Ministry of State Security and People's Liberation Army, using mass internet scanning and compromised routers, cameras, and internet-connected devices to disguise attack origins. The FBI later seized three domains powering the group's QScan and QTRouter platforms, cutting off communications and authentication infrastructure to cripple their operations.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Chinese state-linked hackers operating as the group QTFY stole sensitive data from more than 300 organizations worldwide and breached three U.S. Department of Energy national laboratories, the National Institutes of Health (NIH), and the Health Resources and Services Administration before the FBI dismantled their hacking infrastructure. According to unsealed court records, QTFY operated through a China-based company that the FBI said sold hacking services to clients including China's Ministry of State Security and the People's Liberation Army. Former PLA members were employed by the company and leveraged military relationships to secure contracts and subcontracts for offensive cyber operations. The group combined mass internet scanning with a network of compromised routers, cameras, and other internet-connected devices that disguised the origin of their attacks. By routing malicious traffic through devices located near a victim's network, the hackers made their activities blend in with legitimate local traffic, complicating attribution and tracing efforts by federal investigators.

In May 2024, QTFY exploited a recently disclosed Check Point vulnerability while scanning U.S. power and telecommunications companies and succeeded in stealing data from more than 300 organizations in the United States and abroad, according to a joint advisory from the FBI, NSA, and Cyber National Mission Force. The victims included U.S. defense contractors, financial institutions, and universities, though the government did not publicly name the affected organizations or describe what specific information was taken. Four months later, in September 2024, the hackers exploited zero-day vulnerabilities in Ivanti Cloud Services Appliance software to gain access to three Department of Energy national laboratories, the National Institutes of Health, the Health Resources and Services Administration, and a U.S. security-device manufacturer. The advisory did not disclose what information was accessed during the Ivanti-based intrusions, how long the hackers remained inside the compromised networks, or whether the breaches disrupted operations at any of the affected agencies.

Beyond the successful intrusions, QTFY also conducted numerous unsuccessful attempts against high-value U.S. targets. In 2019, the group attempted to break into NASA by exploiting a vulnerability in the agency's virtual private network, but the attempt failed because NASA had already patched the flaw. In March, the group scanned Senate and hospital-system networks, and in June, they scanned a U.S. election system, though these efforts failed to gain access according to federal authorities. Federal authorities said QTFY also targeted the Justice Department, the Federal Reserve, Senate systems, power companies, hospitals, telecommunications providers, defense contractors, and election infrastructure more broadly. The group operated two main platforms: QScan, which hunted for vulnerable systems, and QTRouter, which masked hackers' identities by routing their traffic through compromised devices. On a single day in 2024, QScan processed more than 2 million scanning and penetration-testing tasks and contained more than 200 proof-of-concept exploits, searching the internet for vulnerable software, exposed services, and other openings that hackers could exploit.

The Department of Justice and FBI seized three domains on Wednesday that powered QTFY's QScan and QTRouter platforms, cutting off the domains used for core communications and authentication. Federal authorities stated that the seizures crippled both platforms by severing the infrastructure necessary for their operation. The investigation revealed the massive scale of QTFY's operations, with the group functioning as part of a broader Chinese cyber ecosystem that the FBI characterized as blurring the line between commercial cybersecurity and state-sponsored operations. Attorney General Todd Blanche stated that "state-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted" in announcing the seizures. The takedown added to a series of FBI operations aimed at dismantling infrastructure used by Chinese government-linked hacking groups, including the 2023 disruption of a botnet used by Volt Typhoon, the 2024 disabling of a botnet linked to Flax Typhoon, and the prior removal of PlugX surveillance malware from more than 4,000 U.S. computers infected by Mustang Panda.

Sources

Sources available to members: 1 source.

CSIDB