DistantNews
Support us
US Disrupts Chinese Hacking Operations Targeting NASA, Federal Reserve, and Other Institutions
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Conflict & Security

US Disrupts Chinese Hacking Operations Targeting NASA, Federal Reserve, and Other Institutions

From Dong-A Ilbo · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

News Sources not specified Outcome reported
  • The U.S. Department of Justice announced it has disrupted hacking attempts by China-linked hackers targeting major institutions including NASA and the Federal Reserve.
  • The hackers used platforms named 'QScan' and 'QTRouter,' which infected Internet of Things devices to disguise the origin of malicious communications.
  • These platforms were operated by a Chinese company whose clients included China's Ministry of State Security and the People's Liberation Army, with intrusions dating back to at least 2018.

The U.S. Department of Justice has successfully disrupted a significant cyber threat, thwarting hacking attempts by China-linked actors targeting critical American institutions. The operation, announced on Tuesday, aimed to neutralize a sophisticated hacking network that had been probing sensitive government and research networks.

Central to the disruption were the 'QScan' and 'QTRouter' hacking platforms. These tools infected Internet of Things devices, creating a complex network to mask the true origin of malicious communications. The Justice Department seized domains associated with these platforms, effectively dismantling a key component of the cyberattack infrastructure.

Investigations revealed that these platforms were operated by Nanjing-based Xinzhuiwei Network Technology Company. Notably, the company's client list reportedly includes entities such as China's Ministry of State Security and the People's Liberation Army, suggesting a state-sponsored element to the hacking activities.

Court documents indicate that these hackers have been active since at least 2018, targeting critical infrastructure and networks globally. Past attempts included a failed effort in August 2019 to access NASA's network by exploiting VPN vulnerabilities. More recent intrusions in September 2024 targeted three Department of Energy research labs, the National Institutes of Health, and a U.S. security equipment manufacturer.

The U.S. Federal Bureau of Investigation (FBI) had previously alerted Congress in March about hackers compromising networks linked to individuals under FBI investigation, identifying China-linked forces as the perpetrators. The hackers have also been implicated in intrusions into the networks of a U.S. House of Representatives committee and several major telecommunications companies in recent years. China has consistently denied allegations of state-sponsored hacking.

The number of companies providing niche attack services has exploded over the past decade.

โ€” Dakota CaryDakota Cary, a China analyst at cybersecurity firm SentinelOne, commented on the proliferation of such services.
About this summary

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.