What banks can do about the latest Chinese hacking campaign

DOJ Announces Charges Against Top Members Of Mexico Cartel CJNG
Todd Blanche, acting U.S. attorney general, left, and Kash Patel, director of the FBI
Aaron Schwartz/Bloomberg
  • Key insight: Three of the four victims the affidavit details are financial or insurance firms.
  • What's at stake: A bank that runs any of the products named in the advisory has to work out whether those machines were exposed during the years the group was exploiting them, which is a question about historical logs rather than about new attacks.
  • Forward look: The seizures made both tools inoperable, but "the Chinese market isn't short on scanning services, so this probably won't deter operations over the medium to long term," according to ETH Zurich researcher Eugenio Benincasa.

Overview bullets generated by AI with editorial review.

Processing Content

The Justice Department and FBI seized platforms on Wednesday that China state-sponsored hackers used to target critical U.S. infrastructure.

The details the government shared about the case affect all banks (which are considered critical infrastructure), and especially point to the dangers of not patching software vulnerabilities in a timely manner.

An FBI affidavit filed in federal court in San Diego documents the campaign; the attackers stole server configuration files and user account details from more than 300 organizations in the United States in a single 2024 campaign. Financial institutions were among the victims.

Agents seized three domains running QScan, which scanned the internet for vulnerable machines and broke into them; and QTRouter, a network built to disguise where an attack came from.

The FBI, the National Security Agency and the Cyber National Mission Force published a 36-page advisory about the cyber campaign, also on Wednesday.

The advisory lists roughly 390 indicators of compromise, which are the addresses and file signatures for which a bank can search its own logs to determine whether the campaign reached its own networks.

The government attributes QScan and QTRouter to QTFY, a group employed by Nanjing Xinjiuwei Network Technology Co. that sells hacking services to China's Ministry of State Security and the People's Liberation Army, according to the Justice Department's announcement.

The Chinese embassy did not respond to a request for comment from American Banker. A spokesperson told Reuters the embassy was not familiar with the specifics of the case but that the Chinese government "firmly opposes and combats all forms of cyberattacks in accordance with the law."

Exploiting unpatched software is now the most common way attackers get into financial-services firms, accounting for 22% of the sector's breaches, according to Verizon's 2026 Data Breach Investigations Report.

The Wednesday advisory said QTFY has used that method against remote-access and network security products, including equipment made by Check Point, Pulse Secure, Citrix, Ivanti and BeyondTrust, since 2019.

No bank has been named as a victim in the campaign; the affidavit identifies its victims by pseudonym, and the U.S. has not named any of the 300-plus organizations the threat actors robbed in 2024.

Who got hit

The victims of that 2024 campaign included U.S. defense contractors, financial institutions and universities, according to the advisory, though it does not break them out by sector or say how many were banks.

The affidavit documents a selection of four earlier victims (including three financial or insurance firms) that had each complained about suspicious activity. The attackers ran those attacks from servers they leased from Hostwinds, a U.S. hosting company, so all four sent their abuse complaints there.

A financial group in South Korea reported that the released addresses were scanning its network. A financial group in Michigan listed eight of them attacking it over roughly a month. An insurance agency in Missouri reported that it was targeted through a flaw in Citrix networking equipment.

The fact that three of the four anecdotes in the affidavit related to financial institutions is mostly a reflection of how the sector behaves rather than a sign of a targeted campaign, according to Mark Orsi, chief executive of the Global Resilience Federation and previously a cybersecurity executive at large banks.

Financial institutions "tend to have stronger detection, reporting and information-sharing capabilities which can make them more visible in investigations," Orsi told American Banker.

Another expert was skeptical that the group was targeting the financial sector at all.

"I haven't followed this group, but this does not sound like any major targeting of the finance sector," said Jason Healey, a senior research scholar at Columbia University. Healey previously served as vice chair of the Financial Services Information Sharing and Analysis Center.

What to do with the 390 indicators

While a bank reacting to the Wednesday advisory might instinctively look to block the addresses it lists, that is actually one of the last steps it should take, according to Orsi, the former bank security executive.

An initial review of the indicators "is not a heavy lift for a midsize bank," Orsi said, but someone has to triage the results.

A bank without sufficient staff should route the advisory to its managed security provider or incident-response firm for a sweep of old logs, he advised. This keeps the workload for the bank staff manageable.

Read more:

If the bank runs any of the products named in the advisory, it should confirm they were patched and work out whether they were exposed during the relevant period, Orsi advised.
Much of that is already automatic, Healey told American Banker. What still takes a person is checking the Chinese companies named in the advisory against the bank's own business relationships, "or on the other side of any deals." A match "should trigger additional investigation," he said.

The advisory lists three key actions: update software and firmware, and audit for equipment past its end of support; stop leaking operational details through internet-facing applications; and isolate critical systems from edge devices. (Edge devices are the firewalls and remote-access gateways that sit between a bank's network and the internet.)

Institutions stall on that third one, according to Orsi. Most large banks should already have that separation "because this has long been a regulatory expectation," and building it later takes "significant investment and a multi-year program."

Institutions often get stuck "because segmentation is treated as a network project without business agreement on which services are truly critical," Orsi said.

Why traditional measures are insufficient

QTRouter existed to make hostile traffic look ordinary, according to the affidavit; it routed the threat actor's activity through a so-called botnet.

A botnet is a collection of everyday devices such as home routers and security cameras that threat actors have quietly compromised, unbeknownst to the everyday consumers who own the devices.

Botnets offer value to threat actors by helping them mask their activity as normal. The traffic from a botnet comes from the homes and offices of regular people who are browsing the internet like normal.

Indeed, the threat actor in this case proxied its own traffic through this botnet, according to research Lumen Technologies' Black Lotus Labs published alongside the takedown.

That defeats a set of controls banks use in many other cases: blocking internet traffic based on where it appears to come from.

There is no single tool that reliably teases apart regular traffic from malicious traffic when it comes through a botnet, "so detection relies upon behavior and context," Orsi said.

Large banks generally have the tools for that, but detection still is not guaranteed.

Midsize banks can get meaningful coverage from internal controls plus an outside provider, "but likely not with the same depth" as a large bank, he said.

What a takedown wins banks

The seizures the Justice Department announced Wednesday made QScan and QTRouter "inoperable," according to the announcement.

That yielded a disruption, not a total shutdown, according to Adam Hickey, a partner at law firm Mayer Brown who established the Justice Department's national security cyber program.

"It's true that actors can retool, but even that takes some time, so you're disrupting their active hacking activity today," Hickey said.

The seizure also "raises the profile" of the threat actor's methods, "which encourages defenders to develop rules and techniques to detect and prevent" the group's next wave of activity, Hickey told American Banker.

A takedown can probably "dent the market for a while," but not permanently, according to Eugenio Benincasa, a senior cybersecurity researcher at the Center for Security Studies at ETH Zurich. Benincasa studies the Chinese firms that sell these services.

"The Chinese market isn't short on scanning services, so this probably won't deter operations over the medium to long term," said Benincasa.


For reprint and licensing requests for this article, click here.
Cyber Security China Bank technology Risk management Data security Technology
MORE FROM AMERICAN BANKER
Load More