DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department
- 1. The U.S. Department of Justice (DoJ) corrected a press statement, now stating that several U.S. agencies were targets, not victims, of attacks by Chinese threat actors.
- 2. The DoJ's updated statement lists agencies like NASA, Federal Reserve, and Department of Energy as 'among the targets of QTFY,' a change from the initial 'victims' designation.
- 3. The FBI has disrupted domains connected to QTFY's tools, QScan and QTRouter, effectively neutralizing the malware's functions.
Article analysis
Skim this article about "DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims": 3 key takeaways and more.
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
skim AI Analysis | The Hacker News
The Hacker News on DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims: skim's analysis surfaces 3 key takeaways. The DoJ corrected its statement, clarifying that U. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Current Events. News article analyzed by skim.
Summary
The DoJ corrected its statement, clarifying that U.S. agencies were targets, not victims, of Chinese hacking group QTFY. The group, linked to a Chinese company and the MSS, has been active since 2018, targeting various sectors. The FBI disrupted domains associated with QTFY's tools.
Key Takeaways
- The U.S. Department of Justice (DoJ) corrected a press statement, now stating that several U.S. agencies were targets, not victims, of attacks by Chinese threat actors.
- The DoJ's updated statement lists agencies like NASA, Federal Reserve, and Department of Energy as 'among the targets of QTFY,' a change from the initial 'victims' designation.
- The FBI has disrupted domains connected to QTFY's tools, QScan and QTRouter, effectively neutralizing the malware's functions.
Statement Breakdown
- Claimed Facts: 70% of statements the article presents as facts
- Opinions: 20% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article presents factual corrections from a government agency and details technical aspects of cyber threats. However, it relies on an affidavit and press releases, which can be subject to interpretation and may not represent the full picture.
Bias assessment: Technically Focused Reporting. The article's primary focus is on the technical details of cyberattacks and the DoJ's correction. It avoids emotional language and presents information factually, with a neutral tone.
Note: This article reports on a correction made by the U.S. Department of Justice regarding cyberattack claims. It is important to note the distinction between being targeted and being a victim.
Credibility flag: Information Verified
Claimed Facts (7)
- This is a direct statement of fact regarding the DoJ's action.
- This states what the DoJ initially claimed, providing context for the correction.
- This directly quotes the corrected information from the DoJ.
- This presents information from an affidavit, which is presented as factual evidence.
- This is a statement of fact regarding the timeline of the threat actor's activity.
- This describes the scope and impact of the threat actor's actions.
- This reports on a specific action taken by the FBI.
Opinions (5)
- This is a statement from the DoJ explaining their reasoning for the edits, which can be interpreted as their official stance or opinion on the accuracy of their reporting.
- This is an interpretation of the significance of the DoJ's correction.
- The description 'technical quartermaster' is an interpretation of QTFY's role.
- While describing the products, the phrasing 'core products in its arsenal' adds a layer of interpretation about their importance and function.
- The statement that QTFY 'sells access' is an assertion about their business model, which is an interpretation of their activities.
Claims (5)
- The phrase 'is said to have attempted' indicates a claim that is reported but not definitively proven within the article.
- While attributed to Lumen Black Lotus Labs, the claim of 'industrialized creation' and the detailed description of the botnet's function are presented as revelations, which can be subject to interpretation and may not be fully verifiable by the reader.
- This statement about the network's composition is presented as a finding, but without direct evidence provided in the article, it remains a claim.
- The naming of the architecture as 'Fast Labyrinth' and its description as blending malicious and legitimate traffic are presented as facts but are part of a complex technical claim.
- This is an allegation from an affidavit, which is a legal document and not necessarily a proven fact in a general sense. The language used ('can blend in', 'remain undetected') describes a capability that is alleged.
Key Sources
- The Hacker News — Media
- U.S. Department of Justice (DoJ) — Government Agency
- National Aeronautics and Space Administration — Government Agency
- Federal Reserve — Government Agency
- Department of Energy — Government Agency
- Department of Justice — Government Agency
- Department of Health and Human Services — Government Agency
- National Institutes of Health — Government Agency
- U.S. Senate — Government Body
- Nanjing Xinjiuwei Network Technology Co — Private Company
- Ministry of State Security (MSS) — Government Agency
- U.S. Federal Bureau of Investigation (FBI) — Government Agency
- Lumen Black Lotus Labs — Cybersecurity Research Firm
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 31st August 2026.