SECURITY Signal 56
Chinese state-backed hackers reportedly used an IoT proxy botnet to breach NASA, the Federal Reserve and other US agencies
A Justice Department and FBI disclosure details that Chinese state-sponsored actors leveraged compromised IoT devices as a proxy network to infiltrate multiple U.S. federal agencies, including NASA and the Federal Reserve.
The attack shows how insecure IoT equipment can be weaponized to hide attacker infrastructure, making detection and attribution difficult for defenders. Engineers must harden IoT devices and segment networks to prevent them from being co-opted as proxy nodes. The partial takedown of the botnet infrastructure leaves open the possibility of rebuilt proxy networks if underlying devices remain vulnerable.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The operation used the QScan and QTRouter services to identify, infect and route traffic through compromised IoT devices, obscuring the attackers' origin.
The FBI and DOJ seized the associated domains and infrastructure, shutting down the QScan and QTRouter platforms, but did not confirm removal of all compromised devices or persistence inside victim networks.
Victims listed include NASA, the Federal Reserve, the Senate and several other federal agencies, highlighting the breadth of exposure from insecure IoT assets.
THE CLUSTER
↗