The United States announced on Wednesday that it had disrupted a Chinese hacking campaign targeting the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. In a released statement, the U.S. Justice Department revealed that it had taken control of domains used by two hacking platforms known as “QScan” and “QTRouter,” which were utilized in the cyberattacks. The affidavit mentioned the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four undisclosed companies in the U.S. and South Korea as victims of the hackers.
The Chinese Embassy in Washington did not immediately respond to requests for comments. The Justice Department identified Nanjing Xinjiuwei Network Technology Company, a China-based firm, as the operator of the hacking platforms. The company’s clients reportedly include China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei has not provided any comments on the matter.
According to the affidavit, the hacking group’s infrastructure was used to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted to access NASA networks in August 2019 through a virtual private network vulnerability. In September 2024, intrusions were carried out at three Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer.
Government representatives mentioned in the Justice Department’s report did not immediately respond to inquiries. Chinese-linked cyberattacks have targeted various U.S. government and private networks recently. In a separate incident, the FBI informed Congress that hackers had breached agency networks involving individuals under FBI scrutiny, with subsequent reports linking the breach to China. Chinese hackers have also been associated with infiltrating U.S. House of Representatives committee networks and major telecommunications companies in recent years.
Experts monitoring Chinese cyber activities suggest that private contractors often conduct high-profile cyber intrusions on behalf of Chinese government agencies. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, highlighted the significant increase in companies offering specialized offensive services over the past decade.
