The US Justice Department and FBI announced on Wednesday the seizure of domains linked to two Chinese state-sponsored hacking platforms, QScan and QTRouter, allegedly operated by Nanjing Xinjiuwei Network Technology Company. The operation, part of a broader crackdown on Chinese cyber activity, targeted a group known as QTFY, which the US says provided hacking services to China's Ministry of State Security and the People's Liberation Army . The platforms were used to compromise or target a wide range of US entities, including NASA, the Federal Reserve, the US Senate, the Departments of Justice and Energy, and the National Institutes of Health . The FBI affidavit indicates the hacking campaign has been active since at least 2018 .
According to the Justice Department, the hackers breached networks at three Department of Energy laboratories, NIH, HHS, and a US security-device manufacturer in September 2024 . Other victims include hospitals, telecommunications providers, power companies, financial institutions, and defense contractors . The FBI affidavit distinguishes between entities that were successfully breached and those merely targeted, listing DOJ, the Federal Reserve, NASA, and the Senate as "targeted" .
China has rejected the allegations. A spokesperson for the Chinese Embassy in Washington stated that the Chinese government "firmly opposes and combats all forms of cyberattacks" and accused the US of using cybersecurity issues to "smear or discredit China" . Chinese foreign ministry spokesman Lin Jian called the allegations "false information" and described the US as "the world's biggest hacking and surveillance empire" . The full impact of the spying effort remains unclear, and US counterintelligence assessments are likely to remain private .
