Kathmandu— The United States government announced Wednesday that it has disrupted a China-affiliated hacking operation targeting numerous US entities, including NASA, the Department of Justice, the Federal Reserve, and the US Senate. The Justice Department seized two hacking platforms, QScan and QTRouter, allegedly used to compromise internet-connected devices and obscure the origins of attacks dating back to at least 2018. The operation aims to dismantle infrastructure utilized by a China-based firm with ties to both civilian intelligence and military branches of the Chinese government.
Infrastructure Seized
The Justice Department’s announcement detailed the takedown of QScan and QTRouter, platforms used to infiltrate internet-connected devices and mask the source of cyberattacks. According to an affidavit, this infrastructure has been employed to breach critical systems not only within the US but also internationally since 2018. QScan was reportedly utilized to identify and infect thousands of devices like routers and network equipment, which were then integrated into a network managed through QTRouter.
Targets Included Key Government Bodies
Court documents revealed that hackers unsuccessfully attempted to access NASA networks in August 2019. More recently, in September 2024, they successfully breached networks at three Department of Energy laboratories, the National Institutes of Health (NIH), the Department of Health and Human Services (HHS), and a US security-device manufacturer. The Federal Reserve and members of the US Senate were also identified as targets, alongside four companies located in both the United States and South Korea.
Alleged Ties to Chinese Government
The Justice Department alleges that the hacking platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm. They claim the company’s clientele includes China’s Ministry of State Security – its civilian intelligence agency – and the People’s Liberation Army, its military. Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to requests for comment regarding these allegations.
Disrupting Attack Obfuscation
Cybersecurity experts explain that platforms like QScan and QTRouter allow hackers to route attacks through compromised devices located outside of China, making attribution difficult. Richard Hummel, a vice president at SecurityScorecard, explained that “When an intrusion appears to come from a device down the street from the target instead of from overseas, it buys the operator time and makes attribution slow.” He added that taking these platforms offline significantly impacts the hackers’ capabilities.
Part of Broader Counter-Hacking Efforts
This operation is part of a larger series of court-authorized actions targeting what Attorney General Todd Blanche described as “indiscriminate hacking activities” sponsored by China. The FBI’s Cyber Division, along with federal prosecutors in California and the San Diego field office, led this investigation. Chinese-linked hacking campaigns have previously compromised US government and private networks, including those related to ongoing FBI investigations and within the House of Representatives.
While the seizure of these domains disrupts access to the platforms, authorities acknowledge that it does not eliminate all malicious activity associated with the group. Investigations into similar cyberattacks are ongoing.
(With inputs from Al Jazeera)
Originally published on abcnews.com.np.







प्रतिक्रिया दिनुहोस्