The United States announced on Wednesday that it had disrupted a Chinese cyber attack operation that targeted key government entities such as the U.S. Justice Department, NASA, the Federal Reserve, and the Senate. The U.S. Justice Department revealed that it had taken control of domain names linked to two hacking platforms known as “QScan” and “QTRouter,” which were part of the cyber campaign.
According to an affidavit, the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four unnamed companies in the U.S. and South Korea were among the victims of the hackers. The Chinese Embassy in Washington did not respond immediately to requests for comments, as Beijing typically denies involvement in hacking activities.
The Justice Department stated that the hacking platforms were operated by a China-based company called Nanjing Xinjiuwei Network Technology Company, which served clients including China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei has not yet provided a comment in response to the recent developments.
The affidavit mentioned that the cyber group’s infrastructure had been utilized to breach critical networks in the U.S. and globally since 2018. The hackers attempted to infiltrate NASA networks in August 2019 through a virtual private network vulnerability and conducted intrusions at Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer in September 2024.
The agencies and organizations identified as targets by the Justice Department did not immediately comment on the matter. Chinese-linked hacking operations have successfully compromised several sensitive U.S. government and private networks in recent years. Chinese hackers have been associated with breaches in FBI-related networks, U.S. House of Representatives committee networks, and major telecommunications companies.
Experts monitoring Chinese cyber activities suggest that private contractors often carry out significant cyber intrusions on behalf of Chinese government agencies. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, highlighted the surge in companies offering specialized offensive cyber services over the past decade.
