Technology
US disrupts Chinese-linked hacking network that targeted government agencies
Federal authorities seized domains used by a China-based firm to mask cyberattacks against NASA, the US Senate, and other high-profile entities.
The short version
- The US Justice Department announced the seizure of two domains, QScan and QTRouter, used by a China-affiliated hacking operation to target sensitive networks since 2018.
- The infrastructure was run by the China-based Nanjing Xinjiuwei Network Technology Company, which allegedly services China's Ministry of State Security and the People's Liberation Army.
- The seizure disrupts but does not completely eliminate the hacking group's capabilities, according to cybersecurity experts.
Key facts
- The US Justice Department disrupted a China-affiliated hacking operation by seizing the QScan and QTRouter domains.[Al Jazeera]
- The hacking network targeted sensitive US entities including the Department of Justice, the Federal Reserve, the US Senate, and NASA.[Al Jazeera]
- Hackers successfully breached networks at three Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, and a US security-device manufacturer in September 2024.[Al Jazeera]
- The targeted platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients reportedly include China's Ministry of State Security and the People's Liberation Army.[Al Jazeera]
- The QScan and QTRouter domains allowed operators to route cyberattacks through compromised devices outside China to disguise their origin.[Al Jazeera]
What remains uncertain
- Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to requests for comment regarding the allegations.[Al Jazeera]