The United States has disrupted a China-linked hacking operation that targeted sensitive government agencies, including the Department of Justice, NASA, the Federal Reserve and the US Senate.
In an announcement issued on Wednesday, the Justice Department said it had taken down two hacking platforms, QScan and QTRouter, which were used to infiltrate internet-connected devices and conceal the origins of cyberattacks.
According to an affidavit, the infrastructure had been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the US and other countries.
Court documents said hackers unsuccessfully attempted to gain access to NASA’s networks in August 2019. However, in September 2024, they successfully breached the networks of three US Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, and a US manufacturer of security devices.
The Federal Reserve, the US Senate and four unnamed companies in the US and South Korea were also among the identified targets.
The Justice Department said the hacking platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients allegedly included China’s civilian intelligence agency, the Ministry of State Security, and the People’s Liberation Army.
Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to requests for comment from Reuters.
According to the Justice Department’s announcement, QScan was used to identify and infect thousands of internet-connected devices, including routers and other network equipment. The compromised devices were then added to a network controlled through QTRouter.
The network enabled hackers to route cyberattacks through computers and other devices located outside China.
This allowed attacks targeting US organisations to appear as though they originated from devices in other countries or even from systems located near the intended victims.
Chinese-linked hacking campaigns have compromised several sensitive US government and private-sector networks in recent years.
In March, the FBI informed the US Congress that hackers had breached networks at some agencies containing information related to individuals under investigation by the bureau. Subsequent public reports attributed the breach to China.
Chinese-linked hackers have also been associated with attacks targeting networks used by certain US House of Representatives committees, as well as several major telecommunications companies in recent years.
