U.S. says Chinese hackers targeted government departments

U.S. says Chinese hackers targeted government departments
Broken Ethernet cable is seen in front of binary code and words "cyber attack" in this illustration taken, 8 March 2022.
Reuters

The United States has announced a major cybersecurity operation against what officials describe as a long-running Chinese-linked hacking campaign that targeted some of the country's most sensitive government departments and institutions.

The Department of Justice said it had seized internet domains connected to two platforms, known as QScan and QTRouter, which investigators allege were used to support cyber intrusions against U.S. government agencies, research institutions and private companies.

According to American authorities, the operation forms part of a broader effort to dismantle infrastructure used by hackers believed to have been active for years. 

Wide range of targets

Court documents released by the authorities indicate that the hackers allegedly sought access to a number of high-profile organisations, including the Department of Justice, NASA, the Federal Reserve and the U.S. Senate.

Investigators also identified the Department of Energy, the Department of Health and Human Services and the National Institutes of Health among entities affected by the campaign. Several private-sector organisations in the United States and South Korea were also listed as victims.

Officials said the hacking activity appeared to focus on gathering intelligence and accessing sensitive government, scientific and commercial information.

Alleged links to Chinese State clients

According to the Justice Department, the infrastructure was operated by Nanjing Xinjiuwei Network Technology Company, a Chinese firm that U.S. authorities say worked with various Chinese government entities.

American officials allege that clients included both China's civilian intelligence apparatus and the People's Liberation Army. The company has not publicly responded to the accusations.

Beijing rejected the allegations with a spokesperson for the Chinese Embassy in Washington saying that China opposes all forms of cybercrime and acts against such activities under its laws.

The spokesperson also accused the United States of using cybersecurity allegations to tarnish China's reputation and justify restrictions on Chinese businesses.

Campaign traced back several years

Investigators say the hacking campaign dates back to at least 2018 and involved attempts to gain access to critical infrastructure and sensitive networks in multiple countries.

Not every operation was successful. U.S. court filings state that hackers unsuccessfully attempted to breach NASA systems in 2019 by exploiting a vulnerability in a virtual private network. Other targets were reportedly able to prevent the attackers from gaining access.

However, authorities say some operations succeeded. Cybersecurity agencies allege the hackers compromised systems belonging to defence contractors, financial institutions and universities during a series of intrusions in 2024.

In one of the more recent incidents cited by investigators, hackers allegedly penetrated networks linked to several Department of Energy laboratories, health agencies and a U.S. security technology manufacturer.

Growing cyber tensions

The case is the latest chapter in an increasingly tense cyber relationship between Washington and Beijing.

Over the past several years, U.S. officials have repeatedly accused Chinese-linked groups of targeting government networks, telecommunications providers, research institutions and critical infrastructure. China has consistently denied conducting or supporting cyber espionage operations against foreign governments and companies.

Cyber security specialists note that many modern state-backed hacking campaigns rely on private contractors rather than government employees directly. These firms often develop specialised tools and services that can be used for intelligence gathering, surveillance and network intrusion operations.

Analysts say the growing number of private companies offering offensive cyber capabilities has made it increasingly difficult to distinguish between commercial activity and state-sponsored operations.

Part of a broader security challenge

The latest takedown underscores continuing concerns in Washington about the vulnerability of government and critical infrastructure networks.

U.S. agencies including the FBI, National Security Agency and Cyber Command have increasingly focused on identifying foreign cyber threats and dismantling the digital infrastructure used to support them.

While the seizure of domains linked to QScan and QTRouter may disrupt some activity, cybersecurity experts caution that such operations rarely eliminate a threat entirely. Instead, attackers often seek alternative infrastructure and adapt their tactics.

Tags