A hacking organization alleged to be linked to Chinese government agencies carried out extensive cyberattacks against major U.S. government bodies and critical infrastructure, including the Department of Justice, the Federal Reserve (Fed), and the Senate, according to reports. U.S. authorities seized the domains of the hacking platform used in the attack and shut down its operations.
On the 26th (local time), Reuters reported that the U.S. Department of Justice and the Federal Bureau of Investigation (FBI) said they had seized domains related to the hacking platforms "QScan" and "QTRouter," which Chinese government–backed hackers used to attack U.S. critical infrastructure and sensitive networks. The Department of Justice seized the domains with court approval, and operations of the two platforms were halted.
According to court documents released by the Department of Justice, the hackers have used tools they developed themselves since at least 2018 to attack critical infrastructure and sensitive networks in the United States and around the world. Targets included the Department of Justice, the Fed, and the Senate, as well as the National Aeronautics and Space Administration (NASA), the Department of Energy, the Department of Health and Human Services (HHS), and the National Institutes of Health (NIH).
Corporations in the United States and Korea were also affected. Court documents showed that a total of four anonymous corporations in the United States and Korea suffered damage from the hackers. However, the names of the affected corporations, the number of corporations harmed by country, and specific details of the damage were not disclosed.
In particular, the extent of the hackers' access to each agency's network varied. In Aug. 2019, they tried to infiltrate NASA's network by exploiting vulnerabilities in a virtual private network (VPN) but failed. In Sept. 2024, they were found to have actually infiltrated three Department of Energy–affiliated laboratories, one institution under the NIH and HHS, and a U.S. security equipment manufacturer. In March this year, they probed and attempted to breach vulnerabilities in the Senate and U.S. hospital networks, but did not succeed.
U.S. authorities currently believe the two platforms used in the attack were operated by Nanjing Xinjiuwei Network Technology Company. According to the Department of Justice, the Chinese government–backed hacking group "QTFY" was employed by Nanjing Xinjiuwei Network to develop and run QScan and QTRouter. QTFY was found to have provided hacking services to clients including the Ministry of State Security (MSS) and the People's Liberation Army (PLA). Some QTFY members are reportedly former members of the PLA.
QScan and QTRouter were found to work in tandem. QScan scanned Internet of Things (IoT) devices worldwide, infecting those vulnerable to hacking, and the compromised devices were incorporated into the QTRouter network. In particular, QTRouter made it appear that hacker communications originated from devices outside China, making it difficult to trace the source of the attacks.
Cases of hacking groups linked to China attacking U.S. government agencies and private corporations have been mounting. In March, the FBI notified Congress that hackers had breached parts of FBI networks related to investigative subjects. Subsequent public reports pointed to hackers linked to China. In addition, hackers linked to China are also known to have hacked networks of some House committees and major telecommunications companies in recent years.
Dakota Cary, a China analyst at cybersecurity firm SentinelOne, assessed that the number of private companies in China offering specific cyberattack services has surged over the past decade. The analysis noted that instead of carrying out cyberattacks directly, Chinese government agencies are increasingly relying on private firms to conduct cyber intrusions.
The Chinese government denied the allegations. A spokesperson for the Chinese embassy in the United States said they were not aware of the specific details in the Department of Justice's announcement, but noted that the Chinese government opposes all forms of cyberattacks in accordance with the law and is cracking down on them. The spokesperson also argued that the United States is using cybersecurity issues to smear China and imposing discriminatory restrictions on Chinese corporations under the pretext of national security.