The United States has disrupted an alleged Chinese state-sponsored cyber-espionage operation linked to breaches targeting several sensitive government institutions, including the Department of Justice (DOJ), NASA, the Federal Reserve and the US Senate.
The DOJ and FBI announced on Wednesday that they had obtained court orders to seize domains associated with two hacking platforms, QScan and QTRouter, rendering the infrastructure inoperable.
According to court documents, QScan functioned as a scanning and exploitation platform, while QTRouter was allegedly used to conceal the origin of cyber intrusions attributed to Chinese government-linked actors.
US investigators identified the operation as being associated with QTFY, allegedly operated through China-based Nanjing Xinjiuwei Network Technology Company. The company’s clients were said to include China’s Ministry of State Security and the People’s Liberation Army.
The DOJ said infrastructure connected to the operation had been used since at least 2018 to target critical infrastructure and sensitive computer networks in the United States and other countries.
Beyond the DOJ, NASA, Federal Reserve and Senate, investigators said the operation also targeted the US Departments of Energy and Health and Human Services, the National Institutes of Health, as well as private companies in the US and South Korea.
US authorities described the domain seizures as part of broader efforts to disrupt foreign cyber-espionage networks targeting government agencies, businesses and critical infrastructure.
Cybersecurity analysts said the case highlights the growing role of private contractors in conducting sophisticated cyber operations allegedly on behalf of Chinese government agencies.
Dakota Cary, a China analyst with cybersecurity firm SentinelOne, said the number of companies offering specialised offensive cyber services in China had increased significantly over the past decade.
The Chinese Embassy in Washington had not immediately commented on the allegations. Beijing has repeatedly denied involvement in cyberattacks attributed to Chinese state-linked actors.
US officials said the seizure of the hacking platforms would significantly disrupt the group’s ability to launch further cyber intrusions and conceal the source of its operations.