US Disrupts Chinese Hacking Operation Targeting Justice Department, NASA and Federal Reserve
The United States says it has disrupted a Chinese hacking operation linked to cyber intrusions targeting the US Justice Department, NASA, the Federal Reserve, the US Senate and other sensitive government agencies.
The US Justice Department said on Wednesday that it had seized domains used by two hacking platforms, known as “QScan” and “QTRouter”, which investigators said were used in the cyber campaign.
According to an affidavit filed by the department, victims of the operation included the US Department of Energy, the Department of Health and Human Services, the National Institutes of Health, as well as four unnamed companies in the United States and South Korea.
The Justice Department said the platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients allegedly included China’s civilian intelligence agency, the Ministry of State Security, and its military, the People’s Liberation Army.
The affidavit said the group’s computer infrastructure had been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and around the world.
The department’s action forms part of a broader US effort to disrupt cyber operations that American officials say pose a threat to government institutions and critical infrastructure.
The Chinese Embassy in Washington did not immediately respond to a request for comment. Beijing routinely denies responsibility for cyberattacks attributed to Chinese actors.
Cybersecurity experts who track Chinese hacking activity say private contractors frequently conduct high-profile intrusions on behalf of various Chinese government agencies.
Dakota Cary, a China analyst with cybersecurity company SentinelOne, said the number of companies providing specialised offensive cyber services in China has grown significantly.
“Over the last decade, the number of companies offering niche offensive services has exploded,” Cary said.
US authorities said the investigation had identified the infrastructure and platforms allegedly used to support the hacking campaign, allowing them to seize the associated domains and disrupt the operation.
Boluwatife Enome
Follow us on: