The United States announced that they have dismantled a Chinese hacking operation responsible for intrusions and unauthorized access attempts targeting the Department of Justice, NASA, the Federal Reserve, the Senate, and other sensitive government agencies. According to authorities, hackers have been targeting sensitive networks in the U.S. and globally since 2018.
The Department of Justice stated in a release that they have taken control of domains used by two hacking platforms – named QScan and QTRouter – which they said were used in the said campaign.
An official statement filed in court listed the victims of the hackers as the U.S. Department of Energy, the Department of Health, the National Institutes of Health, as well as four unidentified companies from the U.S. and South Korea, as reported by Reuters.
The Department of Justice specified that the platforms were managed by a China-based company, Nanjing Xinjiuwei Network Technology Company. Among its clients were China's intelligence service and the People's Liberation Army.
What the Chinese attempted to do
The U.S. Department of Justice states that hackers used their own tools to compromise critical infrastructure and other sensitive networks in the U.S. and worldwide, at least starting from 2018.
The document mentions that not all attempts to gain access were successful. Hackers unsuccessfully attempted to breach NASA networks in August 2019, targeting a vulnerability in a virtual private network (VPN).
In September 2024, hackers intruded into the systems of three unnamed laboratories of the Department of Energy, the National Institutes of Health, an agency within the Department of Health, and an American security equipment manufacturer.
A joint cybersecurity alert issued by the FBI, NSA, and the U.S. Cyber National Mission Force detailed numerous hacking attempts over the years. These included data theft from defense contracting companies, financial institutions, and universities in May 2024.
Additionally, in March 2026, hackers scanned networks for vulnerabilities and made unsuccessful attempts to access the U.S. Senate systems and a U.S. hospital.
Chinese hackers also targeted the House of Representatives
In recent years, hacking campaigns associated with China have compromised a series of sensitive networks, both governmental and private, in the U.S.
In March, the FBI informed Congress that hackers breached certain agency networks related to individuals under investigation, information later made public, attributing this incident to China.
Furthermore, hackers associated with China have been involved in compromising networks of committees in the U.S. House of Representatives, as well as networks of several major telecommunications companies.
Experts monitoring China's cyber activities state that private firms contracted frequently conduct large-scale intrusions on behalf of various Chinese government agencies.
"In the past decade, the number of companies offering specialized cyber attack services has grown explosively," said Dakota Cary, an analyst specializing in China issues at the cybersecurity company SentinelOne.
T.D.
