The United States revealed on Wednesday that it had disrupted a Chinese hacking operation that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government agencies. The U.S. Justice Department announced that it had taken control of domains used by two hacking platforms named “QScan” and “QTRouter,” which were part of the cyber campaign. An affidavit listed the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four unnamed companies in the U.S. and South Korea as victims of the hackers.
The Chinese Embassy in Washington did not respond immediately to requests for comments. The Justice Department stated that the hacking platforms were operated by a China-based company, Nanjing Xinjiuwei Network Technology Company, with clients including China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei did not provide an immediate comment on the matter.
According to the affidavit, the hacking group’s computer infrastructure was used to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted unsuccessfully to access NASA networks in August 2019 and intruded into Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer in September 2024.
The agencies and government organizations mentioned by the Justice Department as targets did not respond immediately to requests for comments. Chinese-linked hacking incidents have compromised various U.S. government and private networks in recent times. In a separate incident, the FBI informed Congress in March about hackers breaching certain agency networks related to individuals under FBI scrutiny, with subsequent reports linking the breach to China. Chinese-linked hackers have also been associated with infiltrating U.S. House of Representatives committee networks and major telecommunications companies in recent years.
Experts monitoring Chinese cyber activities suggest that private contractors often conduct significant cyber intrusions on behalf of different Chinese government entities. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, noted that there has been a surge in companies offering specialized offensive services over the past decade.
