The United States announced on Wednesday that it had disrupted a Chinese hacking campaign that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. The U.S. Justice Department revealed that it had taken control of domains used by two hacking platforms known as “QScan” and “QTRouter,” which were part of the cyber campaign. An affidavit listed the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), as well as four unnamed American and South Korean companies as victims of the hackers.
The Chinese Embassy in Washington did not respond immediately to requests for comments, in line with Beijing’s usual denial of involvement in hacking activities. The Justice Department disclosed that the hacking platforms were operated by the Nanjing Xinjiuwei Network Technology Company, which catered to clients including China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei did not provide an immediate comment upon request.
According to the affidavit, the group’s computer infrastructure was used to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted to access NASA networks unsuccessfully in August 2019 by exploiting a virtual private network vulnerability. In September 2024, breaches were carried out at three Energy Department laboratories, the NIH, an undisclosed HHS agency, and a U.S. security device manufacturer.
The agencies and government organizations identified as targets by the Justice Department did not respond immediately to requests for comments. Chinese-affiliated hacking operations have targeted numerous sensitive U.S. government and private networks in recent times. The FBI informed Congress in March about hackers infiltrating specific agency networks related to individuals under FBI scrutiny, with subsequent reports attributing the breach to China. Chinese-linked hackers have also been associated with compromising U.S. House of Representatives committee networks and various major telecommunications companies.
Experts monitoring Chinese cyber activities suggest that private contractors often conduct high-profile intrusions on behalf of different Chinese government agencies. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, highlighted the significant growth in companies providing specialized offensive services over the past decade.
