The United States revealed on Wednesday that it had disrupted a Chinese cyberattack operation that targeted the U.S. Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government entities. The U.S. Justice Department announced that it had taken control of domain names linked to two hacking platforms known as “QScan” and “QTRouter,” which were utilized in the attacks.
According to an affidavit, the U.S. Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four unnamed U.S. and South Korean companies were among the victims of the hackers. The Chinese Embassy in Washington did not immediately respond to requests for comments, as Beijing typically denies involvement in hacking activities.
The Justice Department disclosed that the hacking platforms were operated by a Chinese company called Nanjing Xinjiuwei Network Technology Company, whose clients reportedly include China’s Ministry of State Security and the People’s Liberation Army. Nanjing Xinjiuwei has not yet provided a response to the allegations.
The affidavit outlined that the cybercriminal group had been targeting critical infrastructure and sensitive networks in the U.S. and globally since at least 2018. The hackers attempted to breach NASA networks in August 2019 through a virtual private network vulnerability and conducted intrusions at Energy Department laboratories, the NIH, an undisclosed HHS agency, and a U.S. security device manufacturer in September 2024.
Despite the Justice Department’s identification of the targeted agencies and organizations, their representatives did not immediately comment on the matter. Chinese-affiliated hacking operations have been linked to various breaches in sensitive U.S. government and private networks in recent years.
In a separate incident, the FBI informed Congress in March about hackers infiltrating agency networks associated with individuals under FBI scrutiny, with subsequent reports attributing the breach to China. Chinese-linked hackers have also been implicated in compromising U.S. House of Representatives committee networks and several major telecommunications companies.
Cybersecurity experts monitoring Chinese cyber activities suggest that private contractors often conduct significant cyber intrusions on behalf of different Chinese government entities. SentinelOne’s China analyst, Dakota Cary, highlighted the proliferation of companies offering specialized offensive services over the past decade.

