U.S. Law Enforcement Disrupts Chinese Hacking Operation Targeting Sensitive Government Networks

The affidavit named additional victims beyond NASA, the Federal Reserve, the U.S. Senate and DOJ: the U.S. Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the United States and South Korea.
The two hacking platforms, QScan and QTRouter, were run by the Nanjing Xinjiuwei Network Technology Company with clients reportedly including China’s civilian intelligence agency, the Ministry of State Security, and the People’s Liberation Army, and are linked to a China-based group identified as QTFY.
Attorney General Todd Blanche described the operation as the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China.
Cybersecurity expert Dakota Cary of SentinelOne noted that over the past decade the number of companies offering niche offensive services has exploded, underscoring the growing private-offense cyber capabilities market.
Beijing routinely denies responsibility for hacking activity, and the Chinese embassy in Washington did not immediately respond to requests for comment.
The U.S. disrupted a major Chinese hacking operation targeting NASA, the Federal Reserve, the Justice Department, and the Senate by seizing two platforms used to infiltrate critical networks AllSides. The operation, run by Nanjing Xinjiuwei Network Technology, served clients including China's Ministry of State Security and the People's Liberation Army Global News. The platforms—QScan and QTRouter—operated as a global botnet and hacking service since at least 2018, compromising sensitive U.S. and international targets.
Attorney General Todd Blanche called the action part of a broader strategy to dismantle state-sponsored hacking campaigns AllSides. The affidavit revealed additional victims beyond the four high-profile agencies: the Department of Energy, Health and Human Services, National Institutes of Health, and four unnamed companies in the U.S. and South Korea.
QScan and QTRouter functioned as botnet-based hacking services available to paying clients Independent. These platforms enabled intrusions into networks worldwide without requiring direct attribution to Beijing. The operation spanned years, with documented activity reaching back to at least 2018, suggesting a sustained, systematic campaign against U.S. critical infrastructure.
Nanjing Xinjiuwei Network Technology was not a government agency—it was a private firm selling hacking services to state clients Global News. This model reflects a growing trend. Cybersecurity expert Dakota Cary of SentinelOne noted that over the past decade, the number of companies offering niche offensive cyber services has exploded AllSides. Private contractors now conduct intrusions for government clients, blurring lines between corporate and state-backed operations.
China's government has routinely denied responsibility for hacking activity AllSides. The Chinese embassy in Washington did not immediately respond to requests for comment on the disruption. Such denials are standard practice, even when evidence links operations to state intelligence agencies or military units like the People's Liberation Army.
Attorney General Todd Blanche framed the domain seizure as part of a series of technical operations designed to dismantle indiscriminate hacking activities sponsored by the People's Republic of China AllSides. The U.S. strategy combines domain seizures, law enforcement actions, and public disclosure to disrupt and expose state-sponsored campaigns. The operation signals an escalating effort to combat the growing sophistication of Chinese state-backed cyber espionage.
Publishers
28
Articles
90
Reach
118