US authorities say they disrupted an alleged Chinese hacking campaign that targeted the Justice Department, NASA, the Federal Reserve, the Senate and other sensitive networks.
The Justice Department said it seized domains connected to two Chinese hacking platforms, known as QScan and QTRouter. Officials say attackers used the platforms to scan for vulnerabilities, gain access to systems and support cyber operations against targets in the United States and elsewhere.
China denied involvement in cyberattacks and accused the United States of using cybersecurity allegations to discredit the country.
DOJ names QScan and QTRouter
The Justice Department said a China-based company, Nanjing Xinjiuwei Network Technology Company, operated the platforms. According to the department, the company’s clients included China’s Ministry of State Security and the People’s Liberation Army.
US authorities say the Chinese hacking platforms supported intrusion attempts against government agencies, critical infrastructure and private-sector organisations from at least 2018.
The government’s affidavit named the Department of Energy, Department of Health and Human Services, National Institutes of Health and several unnamed companies in the United States and South Korea as targets or victims.
Nanjing Xinjiuwei had not publicly responded to the allegations at the time of reporting.
Campaign included successful and failed attempts
The affidavit says the operators did not succeed in every attack. In August 2019, they reportedly tried but failed to access NASA networks through a virtual private network vulnerability.
In September 2024, the hackers allegedly breached three unnamed Department of Energy laboratories, the NIH, an unnamed HHS agency and a US security-device manufacturer.
A joint advisory from the FBI, NSA and US Cyber Command’s Cyber National Mission Force also described alleged data theft from unnamed defence contractors, financial institutions and universities in May 2024.
The advisory said the group scanned for vulnerabilities and attempted to access US Senate and hospital networks in March 2026. Those attempts reportedly failed.
China rejects the allegations
A spokesperson for the Chinese Embassy in Washington said the embassy did not know the specific details in the Justice Department’s statement.
The spokesperson said China opposes cyberattacks and described the US allegations as an attempt to smear or discredit the country. China also criticised what it called the US expansion of national-security restrictions on Chinese companies.
The US government maintains that China-linked contractors carry out cyber operations on behalf of state agencies. Security researchers say the market for specialised offensive cyber services has grown significantly over the past decade.
Federal networks remain frequent targets
The alleged campaign highlights the continued focus on government systems, research organisations, critical infrastructure and organisations that hold sensitive data.
Authorities use domain seizures to limit an operation’s infrastructure and disrupt access to tools. However, a seizure does not always remove the underlying threat, as operators can create replacement domains, servers and malware.
The US says its action against the Chinese hacking platforms forms part of a broader effort to identify and disrupt state-linked cyber operations before they compromise sensitive networks.


0 responses to “US Seizes Chinese Hacking Platforms Linked to Federal Intrusions”