The United States announced on Wednesday the disruption of a Chinese hacking scheme that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. The U.S. Justice Department revealed the seizure of domains associated with two hacking platforms named “QScan” and “QTRouter,” which were part of the illicit campaign.
The hacking operation affected the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), as well as four undisclosed companies in the United States and South Korea. The Chinese Embassy in Washington did not respond immediately to requests for comments, in line with Beijing’s typical denial of involvement in hacking activities.
According to the Justice Department, the hacking platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm with clients including China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei did not provide an immediate comment when contacted.
The affidavit detailed that the group’s computer infrastructure had been used to compromise critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted to breach NASA networks in August 2019 and conducted intrusions at Energy Department laboratories, the NIH, an HHS agency, and a security device manufacturer in September 2024.
Government agencies and organizations identified as targets by the Justice Department did not respond immediately to requests for comments. Chinese-linked hacking campaigns have targeted sensitive U.S. government and private networks in recent years.
Experts tracking Chinese cyber activities suggest that private contractors frequently conduct high-profile intrusions on behalf of various Chinese government agencies. The expansion of companies offering specialized offensive services in the past decade has facilitated such cyber operations, according to Dakota Cary, a China analyst at cybersecurity company SentinelOne.
