U.S. Department of Justice and HHS: US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

U.S. Department of Justice and HHS: US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

US Disrupts China-Linked Hacking Operation Targeting Critical Infrastructure

The U.S. Justice Department announced on Wednesday the disruption of a China-affiliated hacking operation that had targeted sensitive government and private sector networks since at least 2018. The operation dismantled two key hacking platforms, QScan and QTRouter, used to infiltrate internet-connected devices and obscure the origin of cyberattacks.

The hackers, linked to Nanjing Xinjiuwei Network Technology Company, allegedly served clients including China’s Ministry of State Security and the People’s Liberation Army. Targets included the U.S. Department of Justice, NASA, the Federal Reserve, the U.S. Senate, and three Department of Energy laboratories, as well as the NIH, HHS, and a U.S. security-device manufacturer. Four unnamed companies in the U.S. and South Korea were also compromised.

In August 2019, the group attempted but failed to breach NASA networks. By September 2024, they successfully infiltrated multiple U.S. agencies and private entities. The hackers used QScan to infect routers and other devices, then routed attacks through QTRouter, making intrusions appear to originate from unrelated locations delaying detection and attribution.

While the domain seizures disrupt the group’s operations, officials caution that the threat may persist. The takedown is part of a broader U.S. effort to counter China-sponsored cyber espionage, which has repeatedly targeted government and corporate networks, including recent breaches of Congressional and telecom systems. Neither the Chinese embassy nor Nanjing Xinjiuwei has commented on the allegations.

Source: https://www.aljazeera.com/news/2026/8/26/us-says-chinese-linked-hackers-attacked-nasa-senate-and-govt-agencies

U.S. Department of Justice TPRM report: https://www.rankiteo.com/company/usdoj

HHS TPRM report: https://www.rankiteo.com/company/hhsgov

"id": "hhsusd1787790978",
"linkid": "hhsgov, usdoj",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'industry': 'Law Enforcement',
                        'location': 'United States',
                        'name': 'U.S. Department of Justice',
                        'type': 'Government'},
                       {'industry': 'Aerospace',
                        'location': 'United States',
                        'name': 'NASA',
                        'type': 'Government'},
                       {'industry': 'Finance',
                        'location': 'United States',
                        'name': 'Federal Reserve',
                        'type': 'Government'},
                       {'industry': 'Legislative',
                        'location': 'United States',
                        'name': 'U.S. Senate',
                        'type': 'Government'},
                       {'industry': 'Energy/Research',
                        'location': 'United States',
                        'name': 'Department of Energy laboratories (3 unnamed)',
                        'type': 'Government'},
                       {'industry': 'Healthcare/Research',
                        'location': 'United States',
                        'name': 'NIH (National Institutes of Health)',
                        'type': 'Government'},
                       {'industry': 'Healthcare',
                        'location': 'United States',
                        'name': 'HHS (Health and Human Services)',
                        'type': 'Government'},
                       {'industry': 'Technology/Security',
                        'location': 'United States',
                        'name': 'Unnamed U.S. security-device manufacturer',
                        'type': 'Private Sector'},
                       {'location': ['United States', 'South Korea'],
                        'name': 'Four unnamed companies (U.S. and South Korea)',
                        'type': 'Private Sector'}],
 'attack_vector': ['Internet-connected devices', 'Routers'],
 'data_breach': {'sensitivity_of_data': 'Sensitive government and corporate '
                                        'data'},
 'date_detected': '2024-09',
 'date_publicly_disclosed': '2024-09-04',
 'description': 'The U.S. Justice Department announced the disruption of a '
                'China-affiliated hacking operation that had targeted '
                'sensitive government and private sector networks since at '
                'least 2018. The operation dismantled two key hacking '
                'platforms, QScan and QTRouter, used to infiltrate '
                'internet-connected devices and obscure the origin of '
                'cyberattacks. The hackers, linked to Nanjing Xinjiuwei '
                'Network Technology Company, allegedly served clients '
                'including China’s Ministry of State Security and the People’s '
                'Liberation Army. Targets included the U.S. Department of '
                'Justice, NASA, the Federal Reserve, the U.S. Senate, and '
                'three Department of Energy laboratories, as well as the NIH, '
                'HHS, and a U.S. security-device manufacturer. Four unnamed '
                'companies in the U.S. and South Korea were also compromised.',
 'impact': {'data_compromised': True,
            'operational_impact': 'Delayed detection and attribution of '
                                  'cyberattacks',
            'systems_affected': ['Government networks',
                                 'Private sector networks']},
 'initial_access_broker': {'entry_point': 'Internet-connected devices and '
                                          'routers',
                           'high_value_targets': ['Government agencies',
                                                  'Critical infrastructure']},
 'investigation_status': 'Ongoing',
 'motivation': ['Espionage', 'State-sponsored cyber operations'],
 'post_incident_analysis': {'corrective_actions': 'Domain seizures to disrupt '
                                                  'operations',
                            'root_causes': 'Use of hacking platforms (QScan '
                                           'and QTRouter) to obscure attack '
                                           'origins'},
 'references': [{'date_accessed': '2024-09-04',
                 'source': 'U.S. Justice Department'}],
 'response': {'containment_measures': 'Domain seizures to disrupt hacking '
                                      'platforms (QScan and QTRouter)',
              'law_enforcement_notified': True},
 'threat_actor': 'Nanjing Xinjiuwei Network Technology Company '
                 '(China-affiliated)',
 'title': 'US Disrupts China-Linked Hacking Operation Targeting Critical '
          'Infrastructure',
 'type': 'Cyber Espionage'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.