The United States announced on Wednesday that it had thwarted a Chinese cyber intrusion operation that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. The U.S. Justice Department confirmed the seizure of domains associated with two hacking platforms named “QScan” and “QTRouter,” which were utilized in the hacking campaign. An affidavit revealed that the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four undisclosed companies in the U.S. and South Korea were among the victims of the hackers.
The Chinese Embassy in Washington did not immediately respond to requests for comments, a common practice as Beijing typically denies involvement in cyberattacks. The Justice Department disclosed that the hacking platforms were operated by a Chinese company, Nanjing Xinjiuwei Network Technology Company, which served clients such as China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei Network Technology Company did not provide an immediate response to requests for comments.
According to an affidavit, the hacking group’s infrastructure was utilized to breach critical infrastructure and sensitive networks in the U.S. and globally since 2018. The hackers attempted unsuccessfully to breach NASA networks in August 2019 by exploiting a virtual private network vulnerability. In September 2024, the hackers conducted intrusions at three Energy Department laboratories, the NIH, an undisclosed HHS agency, and a U.S. security device manufacturer. Representatives of the targeted agencies and government organizations did not respond immediately to requests for comments. Chinese-linked hacking operations have compromised numerous sensitive U.S. government and private networks in recent times.
In March, the FBI informed Congress about cybersecurity breaches in certain agency networks related to individuals under FBI scrutiny, with subsequent reports attributing the breaches to China. Chinese-affiliated hackers have also been linked to cyber intrusions into specific U.S. House of Representatives committee networks and several major telecommunications companies in recent years.
Experts tracking Chinese cyber activities suggest that private contractors are commonly engaged in high-profile cyber intrusions on behalf of various Chinese government entities. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, noted the proliferation of companies offering specialized offensive services over the past decade.
