6 days ago
US Disrupts China-Linked Hackers Targeting Sensitive Agencies
The United States says hackers connected to China broke into or tried to enter important computer systems.
The reported targets included the Justice Department, NASA, the Federal Reserve, and the U.S. Senate.
Other government agencies and companies in the United States and South Korea were also listed as victims.
The Justice Department took control of internet domains linked to two platforms called QScan and QTRouter.
Officials said a China-based company operated those platforms.
They said the company’s reported clients included Chinese intelligence and military organizations.
The affidavit says the computer infrastructure was used since at least 2018.
China’s embassy did not immediately respond, and Beijing regularly denies responsibility for hacking activity.
The United States said it disrupted a Chinese hacking operation linked to breaches or attempted intrusions involving the Justice Department, NASA, the Federal Reserve, and the Senate.
The Justice Department seized domains associated with two alleged hacking platforms, QScan and QTRouter.
An affidavit listed the Energy Department, Health and Human Services, the National Institutes of Health, and four unnamed U.S. and South Korean companies among the victims.
The Justice Department said the platforms were operated by Nanjing Xinjiuwei Network Technology Company, whose reported clients included China’s Ministry of State Security and People’s Liberation Army.
The affidavit said the group’s infrastructure had been used against critical infrastructure and sensitive networks in the United States and worldwide since at least 2018; China’s embassy did not immediately comment.
- Who
- U.S. officials attributed the alleged operation to China-linked hackers and Nanjing Xinjiuwei Network Technology Company; China’s embassy did not immediately comment.
- What
- The United States announced disruption of an alleged hacking campaign and seized domains connected to QScan and QTRouter.
- Where
- Reported victims included U.S. government agencies, four unnamed companies in the United States and South Korea, and sensitive networks worldwide.
- When
- The disruption was announced on Wednesday; the affidavit said the infrastructure had been used since at least 2018.
- Why
- The Justice Department said the platforms were used in a campaign targeting critical infrastructure and sensitive networks.
U.S. Allegations
China’s Position
Responsibility for the intrusions
U.S. Allegations
The United States said a Chinese hacking operation was responsible for breaches or attempted intrusions involving sensitive U.S. agencies and other networks.
China’s Position
The Chinese Embassy did not immediately respond to a request for comment, while Beijing routinely denies responsibility for hacking activity.
Role of the platforms
U.S. Allegations
The Justice Department said QScan and QTRouter were used in the campaign and were operated by Nanjing Xinjiuwei Network Technology Company.
China’s Position
No Chinese response was reported regarding the platforms, the company, or the U.S. allegations.
Government links and contractors
U.S. Allegations
The Justice Department said the company’s reported clients included China’s Ministry of State Security and People’s Liberation Army; experts said private contractors often conduct intrusions for Chinese government agencies.
China’s Position
The reports did not include a Chinese response to the claims about the company’s clients or private contractors.
Key facts
- Alleged operation
- A China-linked hacking campaign involving U.S. government and other sensitive networks
- Reported targets
- The Justice Department, NASA, the Federal Reserve, the Senate, the Energy Department, Health and Human Services, and the National Institutes of Health
- Other reported victims
- Four unnamed companies in the United States and South Korea
- Hacking platforms
- QScan and QTRouter
- U.S. action
- The Justice Department seized domains used by the two platforms
- Reported operator
- Nanjing Xinjiuwei Network Technology Company, a China-based firm
- Reported activity period
- Since at least 2018, according to the affidavit
- Chinese response
- The Chinese Embassy in Washington did not immediately comment; Beijing routinely denies responsibility for hacking activity
Quotes
Dakota Cary
China analyst with cybersecurity company SentinelOne
“Over the last decade, the number of companies offering niche offensive services has exploded.”
telegraphindia.com











