Justice Department seizes QScan, QTRouter domains; hackers active since at least 2018
The United States said Wednesday it had disrupted a Chinese hacking operation responsible for break-ins and attempted intrusions targeting the Justice Department, NASA, the Federal Reserve, the Senate and other sensitive government agencies.
In a statement, the Justice Department said it had seized domains used by two hacking platforms, dubbed QScan and QTRouter, which it said had been deployed as part of the campaign.
An accompanying affidavit identified the US Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the US and South Korea among the hackers' victims.
A spokesperson for the Chinese Embassy in Washington said in an email that while unfamiliar with the specifics in the DOJ statement, "the Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law."
The spokesperson accused the US of using cybersecurity issues to "smear or discredit China," adding that China "opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies."
The Justice Department said the hacking platforms were operated by a China-based firm, Nanjing Xinjiuwei Network Technology Company, whose clients it said included China's Ministry of State Security and the People's Liberation Army.
Nanjing Xinjiuwei did not immediately respond to a request for comment outside normal business hours.
According to the affidavit, the hackers used tools they developed to compromise critical infrastructure and other sensitive networks in the US and worldwide since at least 2018. Not all intrusion attempts succeeded, the hackers unsuccessfully tried to access NASA networks in August 2019 by targeting a virtual private network vulnerability.
In September 2024, the hackers carried out successful intrusions at three unnamed Energy Department laboratories, the NIH, an unnamed HHS agency, and a US security device manufacturer, the affidavit said.
A joint cybersecurity advisory issued by the FBI, NSA and US Cyber Command's Cyber National Mission Force detailed multiple hacking efforts over the years, including successful data theft from unnamed defense contractors, financial institutions and universities in May 2024. The hackers also scanned for vulnerabilities and made unsuccessful attempts to access networks belonging to the US Senate and a US hospital in March 2026.
A NASA spokesperson said the agency does not comment on specific incidents, while the Department of Health and Human Services referred questions to the DOJ, which did not respond to a request for further detail.
Chinese-linked hacking campaigns have compromised a series of sensitive US government and private networks in recent years. In March, the FBI notified Congress that hackers had penetrated certain agency networks tied to individuals under FBI investigation, with public reporting later attributing the breach to China. Chinese-linked hackers have also been tied to intrusions into US House of Representatives committee networks and multiple major telecommunications companies in recent years.
Experts tracking Chinese cyber activity say private contractors routinely carry out high-profile intrusions on behalf of various Chinese government agencies. "Over the last decade, the number of companies offering niche offensive services has exploded," said Dakota Cary, a China analyst at cybersecurity firm SentinelOne.
(0)Comments