The United States announced on Wednesday that it had thwarted a Chinese hacking operation responsible for breaking into the US Department of Justice, NASA, the Federal Reserve, the US Senate, and other sensitive government agencies.
The Justice Department said in a statement that it seized domains used by two hacking platforms, called “QScan” and “QTRouter,” which it said were used as part of the campaign. An affidavit identified the US Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the US and South Korea as among the hackers’ victims.
The Chinese Embassy in Washington did not immediately return a message seeking comment. Beijing routinely denies responsibility for hacking activities.
Get daily national news
Get Canada Daily News delivered to your inbox so you don’t miss the day’s top stories.
The Justice Department said the platforms were operated by a China-based company, Nanjing Xinjiuwei Network Technology Company, which said its clients included China’s civilian intelligence agency, the Ministry of State Security, and its military, the People’s Liberation Army.
Reuters was not immediately able to determine contact details for Nanjing Xingyue.
The group’s computer infrastructure has been used to hack critical infrastructure and other sensitive networks in the United States and around the world since at least 2018, the affidavit said.
Experts who track Chinese cyber activity say private contractors routinely conduct high-profile hacking operations on behalf of various Chinese government agencies.
“Over the past decade, the number of companies providing specialized attack services has risen dramatically,” said Dakota Carey, a China analyst at cybersecurity firm SentinelOne.