US Seizes Infrastructure Linked to Chinese Hacking Network Targeting NASA, Senate and Federal Agencies

RksNews
RksNews 4 Min Read
4 Min Read

The United States has disrupted a China-linked cyber operation that targeted sensitive American institutions, including the Department of Justice, NASA, the Federal Reserve and the U.S. Senate, according to the U.S. Department of Justice.

The Justice Department said it had seized several domains used by two hacking platforms known as QScan and QTRouter, which authorities allege were part of a broader cyber campaign targeting networks in the United States and other countries.

Court documents identified additional targets, including the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, as well as four unidentified companies in the United States and South Korea.

The Chinese Embassy in Washington said it was not aware of the specific details cited by the Justice Department but reiterated that the Chinese government “opposes and combats all forms of cyberattacks in accordance with the law.”

The embassy also accused Washington of using cybersecurity issues to “smear or discredit China” and criticized the use of national security as a justification for imposing restrictions on Chinese companies.

According to the Justice Department, QScan and QTRouter were operated by Chinese company Nanjing Xinjiuwei Network Technology Company. U.S. authorities allege that its customers included China’s Ministry of State Security, the country’s civilian intelligence agency, as well as the People’s Liberation Army.

Campaign dates back to 2018

U.S. authorities said the hacking campaign had been active since at least 2018 and had targeted critical networks in the United States and elsewhere.

Not every intrusion attempt was successful. In August 2019, for example, hackers allegedly attempted to gain access to NASA networks by exploiting a vulnerability in a virtual private network, but the effort failed.

By September 2024, however, court documents indicate that the hackers had successfully breached three Department of Energy laboratories, the National Institutes of Health, an agency within the Department of Health and Human Services, and a U.S. company that manufactures security equipment.

A joint advisory from the FBI, NSA and U.S. Cyber Command detailed additional activity attributed to the network. In May 2024, hackers allegedly stole data from defense companies, financial institutions and universities.

In March 2026, the attackers reportedly scanned the networks of the U.S. Senate and a U.S. hospital for vulnerabilities and attempted to gain access, although those efforts were unsuccessful.

NASA declined to comment on specific incidents, while the Department of Health and Human Services referred questions to the Justice Department.

Growing U.S. concerns over Chinese cyber operations

The operation comes amid growing U.S. concerns over cyberattacks linked to Chinese actors against government agencies, companies and critical infrastructure.

In March, the FBI informed Congress that hackers had compromised several networks belonging to U.S. agencies connected to individuals under investigation by the bureau. Subsequent reporting linked that activity to China.

Chinese-linked hackers have also been accused of targeting networks belonging to congressional committees and major U.S. telecommunications companies.

Cybersecurity experts tracking Chinese cyber activity say private companies increasingly provide sophisticated hacking services to various Chinese government agencies.

“Over the last decade, the number of companies providing specialized cyberattack services has increased significantly,” said Dakota Cary, a China analyst at cybersecurity company SentinelOne.

The latest action highlights Washington’s broader effort to disrupt the infrastructure used by Chinese cyber actors while holding companies and individuals involved in alleged state-backed hacking campaigns accountable.