(Reuters: The U.S. said on Wednesday it had disrupted a Chinese hacking operation responsible for break-ins and attempts on the Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government agencies.
In a statement, opens new tab, the Justice Department said it had seized domains used by two hacking platforms, dubbed QScan and QTRouter, which it said had been used as part of the campaign.
identified the U.S. Department of Energy, Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the U.S. and South Korea as being among the hackers’ victims.
A spokesperson for the Chinese Embassy in Washington said in an email that while they were not familiar with the specifics mentioned in the DOJ statement, the “Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law.”
The U.S. uses cybersecurity issues to “smear or discredit China,” the spokesperson said, and China “opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies.”
The Justice Department said the platforms were run by a China-based firm, the Nanjing Xinjiuwei Network Technology Company, whose clients it said included China’s civilian intelligence agency, the Ministry of State Security, and its military, the People’s Liberation Army.Nanjing Xinjiuwei did not immediately respond to a request for comment outside normal business hours.
The affidavit said the hackers used tools they developed to compromise critical infrastructure and other sensitive networks in the U.S. and worldwide since at least 2018.
The affidavit said that not all their attempts to gain access were successful. The hackers unsuccessfully attempted to gain access to NASA networks in August 2019 by targeting a virtual private network vulnerability.
In September 2024, the hackers carried out intrusions at three unnamed Energy Department laboratories, the NIH, an unnamed HHS agency, and a U.S. security device manufacturer, according to the affidavit.
A joint cybersecurity advisory, opens new tab issued by the FBI, NSA and U.S. Cyber Command’s Cyber National Mission Force detailed multiple hacking efforts over the years. These included successful data theft from unnamed defense contractors, financial institutions and universities in May 2024.
