The United States announced on Wednesday that it had thwarted a Chinese cyber attack targeting the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. The U.S. Justice Department revealed that it had taken control of domains associated with two hacking platforms known as “QScan” and “QTRouter,” which were utilized in the operation. An affidavit specified that the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), as well as four unnamed companies in the U.S. and South Korea were among the victims of the hackers.
The Chinese Embassy in Washington did not respond immediately to requests for comments, in line with Beijing’s usual denial of involvement in hacking activities. The Justice Department disclosed that the hacking platforms were operated by Nanjing Xinjiuwei Network Technology Company, based in China, with clients including China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei has not provided a comment on the matter.
According to the affidavit, the hacker group’s infrastructure has been used to breach critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers made unsuccessful attempts to breach NASA networks in August 2019 by exploiting a virtual private network vulnerability. In September 2024, the hackers infiltrated three Energy Department laboratories, the NIH, an unnamed HHS agency, and a U.S. security device manufacturer.
Responses from the targeted agencies and government organizations mentioned by the Justice Department were not immediately available. Chinese-affiliated hacking campaigns have compromised numerous U.S. government and private networks in recent times. The FBI previously informed Congress of hackers infiltrating certain agency networks related to individuals under FBI investigation, with subsequent reports attributing the breach to China. Chinese hackers have also been linked to breaches of U.S. House of Representatives committee networks and several major telecommunications companies.
Experts monitoring Chinese cyber activities note that private contractors often conduct prominent intrusions on behalf of various Chinese government agencies. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, highlighted the significant growth in companies offering specialized offensive services in the past decade.



