Chinese Hackers Breached NASA, Federal Reserve, Justice Department and US Senate in Massive Cyber Campaign, Feds Say
Chinese state-sponsored hackers penetrated computer systems belonging to some of the most sensitive institutions in the United States — including NASA, the Federal Reserve, the Justice Department and the US Senate — as part of a sprawling cyber campaign that has been operating for years, federal authorities revealed Wednesday.
The Justice Department and FBI announced that they have now disrupted the operation by seizing three internet domains critical to two sophisticated hacking platforms known as QScan and QTRouter. Because those domains were built directly into the platforms and were necessary for their operation, authorities said the seizures rendered both systems inoperable.
Court documents unsealed in the Southern District of California identified the group behind the operation as QTFY, which US authorities described as a Chinese state-sponsored hacking organization operating through Nanjing Xinjiuwei Network Technology Company, a China-based technology firm.
According to the Justice Department, QTFY provided hacking services to paying customers that included two of the Chinese government’s most powerful institutions: the Ministry of State Security, Beijing’s principal civilian intelligence agency, and the People’s Liberation Army.
The scope of the campaign extended across numerous branches and agencies of the US government. Federal authorities identified NASA, the Federal Reserve, the Department of Energy, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the US Senate as victims of QTFY computer intrusion activity.
The hackers also went far beyond government agencies. Court filings indicate that the operation targeted or compromised organizations in critical sectors including hospitals, telecommunications companies, power utilities, financial institutions and defense contractors, along with additional targets in the United States and South Korea.
The two platforms allegedly served different but complementary roles in the operation. QScan was designed to scour the internet for vulnerable systems and devices that could be compromised, allowing the hackers to build up a vast collection of infected machines around the world.
Those compromised devices could then be incorporated into QTRouter, an infrastructure that helped hackers conceal where their attacks were actually coming from. By routing malicious internet traffic through compromised devices located closer to intended targets, attackers could make their activity appear to originate from ordinary or legitimate local users rather than from China.
That capability allowed the hackers to disguise their origins while carrying out espionage and computer intrusions against sensitive targets, making the malicious activity considerably more difficult for defenders to identify and trace.
The campaign stretches back to at least 2018, according to the FBI and National Security Agency, which released a joint cybersecurity advisory Wednesday detailing indicators associated with QTFY’s malicious activities.
One of the incidents examined by investigators involved an attempted intrusion into NASA’s network in 2019. According to an FBI affidavit, the hackers attempted to exploit a vulnerability in the space agency’s systems, but the attack failed because NASA had already installed a patch correcting the weakness.
Attorney General Todd Blanche said the takedown was part of a broader federal campaign aimed at dismantling Chinese government-backed cyber infrastructure targeting American institutions.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” Blanche said.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” he added.
FBI Director Kash Patel characterized the action as the disruption of a global botnet and hacking platform used by Chinese state-sponsored cyber actors.
Authorities have not publicly disclosed the full extent of the information stolen from the compromised federal systems or the total damage caused by the campaign, leaving significant questions about precisely what the hackers were able to access.
Wednesday’s operation is the latest in a series of aggressive US actions against Chinese-linked hacking networks. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 American computers after they were infected by the Chinese state-sponsored group known as Mustang Panda.
A year earlier, federal authorities dismantled a botnet containing hundreds of thousands of compromised internet-connected devices that officials said the Chinese-linked Flax Typhoon group had made available to Chinese government customers.
And in 2023, the FBI disrupted another botnet used by the Chinese state-sponsored Volt Typhoon hacking group to conceal cyber operations targeting critical infrastructure in the United States and other countries.
The latest revelations underscore growing US concerns over China’s use of private technology companies and contractors to conduct or facilitate cyberespionage on behalf of Beijing’s intelligence and military services.
The Chinese Embassy in Washington did not immediately respond to a request for comment regarding Wednesday’s announcement. Beijing has repeatedly denied US allegations that it sponsors malicious hacking operations.
{Matzav.com}
