The U.S. Justice Department announced Wednesday that it had disrupted two Chinese hacking platforms used to infiltrate multiple federal agencies, including the Department of Justice, NASA, the Federal Reserve, and the U.S. Senate, as well as critical infrastructure sectors.
The action targeted the domains of QScan and QTRouter, two platforms operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm. According to court documents, the platforms were employed by a state-sponsored group identified as QTFY, which U.S. officials allege conducted cyber intrusions on behalf of China’s Ministry of State Security and the People’s Liberation Army.
Agencies and sectors affected
The Justice Department’s affidavit listed additional victims, including the U.S. Department of Energy, Department of Health and Human Services, National Institutes of Health, and four unnamed companies in the U.S. and South Korea. Affected sectors spanned hospitals, telecommunications providers, power companies, financial institutions, and defense contractors, with evidence suggesting the intrusions began as early as 2018.
Legal and technical response
Federal authorities seized the domains used by QScan and QTRouter, describing the platforms as tools for targeting U.S. critical infrastructure and sensitive networks. The operation follows a pattern of cyber activity attributed to private contractors working on behalf of Chinese government agencies, according to cybersecurity experts.
Chinese government response
The Chinese Embassy in Washington did not immediately respond to requests for comment. Beijing has historically denied involvement in state-sponsored hacking operations, though U.S. officials have repeatedly accused Chinese entities of conducting cyber intrusions for espionage and intellectual property theft.
Background on the hacking platforms
QScan and QTRouter were designed to compromise networks and exfiltrate data, with court filings indicating their use in global cyber intrusions. The platforms’ infrastructure was linked to Nanjing Xinjiuwei, a company whose clients, per U.S. allegations, include Chinese intelligence and military entities. Reuters was unable to locate contact details for the company.
Expert assessment
Cybersecurity analysts note a growing trend of private firms offering offensive cyber services to state actors. Dakota Cary, a China analyst with SentinelOne, stated that the number of such companies has expanded significantly over the past decade, with many specializing in high-profile intrusions for government clients.