The US government said on May 15 it had disrupted a China-linked cyber campaign targeting sensitive US government agencies, including the Justice Department, NASA, the Federal Reserve and the Senate.
According to the US Justice Department, the operation disabled two attack platforms named QScan and QTRouter, which were used to infiltrate internet-connected devices and conceal the origins of attacks. Court documents show the infrastructure has been used to compromise critical networks in the US and other countries since 2018.
Court records show hackers attempted to access NASA networks in August 2019 but failed. By September 2024, they had successfully breached systems at three Department of Energy labs, the National Institutes of Health (NIH), the Department of Health and Human Services (HHS) and a US security equipment maker. The Fed, the US Senate and four unnamed companies in the US and South Korea were also identified as targets.
The Justice Department said the platforms were operated by Nanjing Xinjiuwei Network Technology, a China-based company. Its clients are believed to include China's Ministry of State Security (MSS) and the People's Liberation Army (PLA). China's embassy in Washington and the company had not commented on the matter.
QScan was used to find and infect thousands of internet-connected devices, including routers and other network gear. These devices were then linked into a network via QTRouter, allowing hackers to route attacks through computers and devices outside China. This made it possible for attacks targeting the US to originate from a device in another country, even one near the victim.
The latest action does not fully shut down the group's activity, but seizing the domains will disrupt access to the platforms. Richard Hummel, vice president at cybersecurity firm SecurityScorecard, said: "When an intrusion appears to come from a device near the target rather than from overseas, it gives the attacker more time and slows attribution. Taking down two platforms of this scale removes real capability they use daily."
The operation is part of a series of court-authorized actions against what Attorney General Todd Blanche described as "indiscriminate cyberattacks" sponsored by China. The FBI, federal prosecutors in California and the San Diego field office led the investigation.
China-linked hacking campaigns have breached numerous sensitive US government and private networks in recent years. In March, the FBI told Congress that hackers had breached networks at several agencies related to people investigated by the FBI, which was later attributed to China. Chinese hackers have also been accused of attacking networks of several US House committees and major telecom companies in recent years.