The US claims to have stopped a hacking campaign with ties to China that was aimed at important federal agencies


The US says it has disrupted a Chinese cyber-espionage operation that allegedly targeted highly sensitive government and critical-infrastructure networks.

What happened

  • The US Justice Department seized domains associated with two hacking platforms, QScan and QTRouter.

  • The platforms were allegedly operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm.

  • According to a US affidavit, the infrastructure had been used since at least 2018 to compromise networks in the US and other countries.

  • Reported victims included NASA, the Federal Reserve, the US Justice Department and the US Senate.

  • Other identified targets included the Department of Energy, Department of Health and Human Services and National Institutes of Health, as well as four unnamed companies in the US and South Korea.

Alleged Chinese government connection

US investigators say Nanjing Xinjiuwei's customers included China's Ministry of State Security (MSS) and the People's Liberation Army (PLA).

This is significant because the US allegation is not simply that a Chinese company carried out hacking for its own benefit. Authorities contend that the company's infrastructure was used to provide offensive cyber capabilities to Chinese intelligence and military organizations.

Cybersecurity analysts say this type of outsourcing has become increasingly common, with private Chinese contractors providing specialised hacking services to government agencies.

Why the operation matters

The alleged targets span some of the most strategically important parts of the US government:

  • NASA → sensitive aerospace and technology information

  • Federal Reserve → highly sensitive economic and financial information

  • Justice Department → law-enforcement and investigative information

  • Senate → government communications and potentially political intelligence

  • Energy Department → critical infrastructure and nuclear-related expertise

The alleged activity dating back to 2018 also points to long-term intelligence collection rather than a single cyberattack.

China has historically rejected accusations that its government directs hacking operations. The Chinese Embassy in Washington had not responded to the latest allegations when the report was published.

Useful next step: the most revealing part of this story is the US affidavit—particularly the evidence investigators cite to connect QScan/QTRouter and Nanjing Xinjiuwei to the MSS and PLA.


 

buttons=(Accept !) days=(20)

Our website uses cookies to enhance your experience. Learn More
Accept !