The United States revealed on Wednesday that it had disrupted a Chinese hacking campaign that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and various sensitive government entities. The U.S. Justice Department announced the seizure of domains utilized by two hacking platforms named “QScan” and “QTRouter,” which were part of the cyber operation. An affidavit mentioned the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four unnamed U.S. and South Korean companies as victims of the hackers.
The Chinese Embassy in Washington did not respond immediately when contacted for a comment, consistent with Beijing’s usual denial of involvement in hacking activities. The Justice Department disclosed that the platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients included China’s Ministry of State Security and the People’s Liberation Army.
The affidavit highlighted that the hacking group’s infrastructure had been used to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted unsuccessfully to breach NASA networks in August 2019 through a virtual private network vulnerability and later infiltrated Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer in September 2024.
The agencies and organizations identified by the Justice Department as targets did not provide immediate comments. Chinese-linked hacking activities have compromised numerous U.S. government and private networks in recent years. The FBI informed Congress in March about hackers accessing specific agency networks related to individuals under FBI scrutiny, with subsequent reports attributing the breach to China. Chinese-affiliated hackers have also been linked to infiltrating U.S. House of Representatives committee networks and several major telecommunications companies.
Experts monitoring Chinese cyber operations suggest that private contractors frequently conduct prominent intrusions on behalf of various Chinese government entities. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, noted the significant increase in companies offering specialized offensive services over the past decade.
