US disrupts China-linked hacking operation targeting NASA, Senate and federal agencies
US authorities say they have disrupted a China-affiliated hacking operation that targeted sensitive government networks in the United States and elsewhere. The Justice Department said two domains used by the group were seized as part of the action, which focused on platforms known as QScan and QTRouter. According to the announcement, the operation had been active since at least 2018 and had been used to conceal the source of attacks against high-value targets.
Sponsored
The targets identified by US officials included NASA, the Department of Justice, the Federal Reserve and the US Senate. Court documents cited in the announcement said hackers unsuccessfully tried to access NASA networks in August 2019. They later succeeded in breaching networks at three Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, and a US security-device manufacturer in September 2024.
Officials said QScan was used to find and infect thousands of internet-connected devices, including routers and other network equipment. Those devices were then folded into a network through QTRouter, allowing traffic to be routed through computers and devices outside China. That method could make an attack appear to come from another country, or even from a device close to the intended target, complicating attribution and response.
The Justice Department said the platforms were run by a China-based company, Nanjing Xinjiuwei Network Technology Company. It said the company's clients included China's civilian intelligence agency, the Ministry of State Security, and the People's Liberation Army. The announcement also identified four unnamed companies in the United States and South Korea as targets, underlining the wider reach of the operation beyond federal institutions.
Sponsored
The case adds to long-running concerns in Washington about cyber activity linked to China and the use of compromised infrastructure to mask attacks. The seizure of domains does not necessarily end the group's activity, but it can disrupt access to the tools and infrastructure used to carry out intrusions. It also highlights the continuing vulnerability of internet-connected devices, which can be turned into relay points for broader campaigns against government and private-sector networks.
What remains unclear is the full extent of the disruption and whether all associated infrastructure has been identified. US officials said the latest action would not eliminate every element of the group's activity, suggesting further work may follow. The response will be watched for any additional disclosures about victims, the scale of the compromise, and whether more seizures or charges are announced.
#cyberattack #Chinalinkedhackers #NASA #USSenate #JusticeDepartment

