The United States announced on Wednesday that it had disrupted a Chinese hacking campaign responsible for infiltrating several U.S. government agencies, including the U.S. Justice Department, NASA, the Federal Reserve, and the Senate. According to a statement from the U.S. Justice Department, they had taken control of domains associated with two hacking platforms known as “QScan” and “QTRouter” that were utilized in the cyber attacks.
An affidavit revealed that the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four undisclosed companies in the U.S. and South Korea were among the targets of the hackers. The Chinese Embassy in Washington did not respond immediately to requests for comments, a common practice as Beijing typically denies involvement in hacking incidents.
The Justice Department identified the Nanjing Xinjiuwei Network Technology Company, a China-based firm, as the operator of the hacking platforms. The company’s clients allegedly include China’s Ministry of State Security, the People’s Liberation Army, and other military and intelligence agencies. Nanjing Xinjiuwei has not provided a comment in response to the allegations.
The affidavit stated that the hacking group had been using their computer infrastructure to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted to breach NASA networks in August 2019 through a virtual private network vulnerability, and in September 2024, they successfully intruded into Energy Department laboratories, the NIH, an HHS agency, and a U.S. security device manufacturer.
The organizations identified as targets by the Justice Department did not immediately comment on the situation. Chinese-affiliated hacking activities have compromised various U.S. government and private networks in recent years. Chinese hackers have been linked to breaches in FBI-related networks and U.S. House of Representatives committee networks, as well as attacks on major telecommunications companies.
Experts monitoring Chinese cyber activities suggest that private contractors frequently conduct high-profile cyber intrusions on behalf of Chinese government entities. Dakota Cary, a China analyst at cybersecurity company SentinelOne, noted a significant increase in companies offering specialized offensive services over the past decade.
