The Justice Department on Wednesday said it shut down several platforms linked to China that hacked the Senate and multiple government agencies.
Officials said a Chinese company linked to the Beijing government hacked into multiple federal agencies, including the Federal Reserve, National Institutes of Health, National Aeronautics and Space Administration, and the Departments of Justice, Energy, and Health and Human Services. The DOJ and FBI seized two domains, QScan and QTRouter, after investigators determined QTFY, or the Nanjing Xinjiuwei Network Technology Company, was using those systems to hack into the Senate, U.S. government agencies, and sensitive networks nationwide, according to officials.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” Attorney General Todd Blanche said.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” he said. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”
The cyberattacks have been taking place since 2018, according to a court affidavit unsealed in the Southern District of California. Hackers also targeted networks operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors, according to the filing.
It remains unclear how successful the hacking attempts were.
U.S. Senate systems were breached this year, an attempted hack of NASA servers took place in August 2019, and an attack on an unidentified Ohio-based medical center occurred in mid-2020, the affidavit said. In 2024, the hackers targeted three Energy Department National laboratories, the National Institutes of Health, and a U.S. security device manufacturer, according to the affidavit.
During a Fox News interview Wednesday, Blanche was asked about whether the cyberattacks would be discussed during Chinese President Xi Jinping’s visit to the U.S. next month, when he will meet with President Donald Trump.
Blanche sidestepped the question, saying he would not “tell President Trump what he needs to talk to the leadership about in China,” but said Chinese hacking “has to stop.”
“This is something that we’ve talked about with our counterparts in China for many, many years,” the attorney general said. “And we know that it’s happening. And they know we know that it’s happening. And it has to stop.”
The DOJ said China’s Ministry of State Security and its military are among QTFY’s customers. QScan searches and automatically infects thousands of devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices, officials said.
AN INSIDE LOOK AT THE STATE OF THE KENNEDY CENTER BEFORE TWO-YEAR RENOVATION
QTRouter works in tandem with QScan, serving as an “obfuscation network” that allows QTFY and other malicious cyber actors to conceal the Chinese origin of their computer intrusion activities “because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks,” according to the DOJ.
“Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries,” Special Agent in Charge Mark Remily of the FBI San Diego Field Office said. “We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”
