US Disrupts China-Linked Hackers Targeting NASA
The United States has disrupted a China-linked cyberespionage operation that targeted sensitive government networks including NASA, the Federal Reserve, the Justice Department and the US Senate. Authorities seized domains supporting two hacking platforms that had allegedly been used against American and overseas networks since at least 2018.
Chinese Hackers Targeted US Government Networks
US investigators identified the hacking group as QTFY, which authorities say operated through China-based Nanjing Xinjiuwei Network Technology Company.
Government records identify NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the Senate among networks targeted or affected by the operation.
Some intrusions were successful while others were attempted attacks. Authorities have not publicly disclosed the full extent of data potentially accessed from each organisation.
US Seizes QScan and QTRouter Platforms
The Justice Department and FBI seized domains supporting two platforms called QScan and QTRouter.
QScan was allegedly used to identify vulnerable internet-connected devices and compromise them. Those devices could then become part of QTRouter, a network designed to conceal where subsequent hacking activity originated.
The system allowed attackers operating from China to make malicious traffic appear to originate from compromised devices elsewhere, including locations close to intended targets.
US Links Operation to Chinese State Agencies
American authorities allege that Nanjing Xinjiuwei provided hacking services to clients including China’s Ministry of State Security and People’s Liberation Army.
China has previously rejected US accusations of state-sponsored hacking and accused Washington of politicising cybersecurity issues.
US officials said the domain seizures have rendered the identified QScan and QTRouter infrastructure inoperable, although authorities have not claimed that the wider cyber threat has been eliminated.







