The Justice Department announced Wednesday that it had seized internet domains used by two Chinese-linked hacking platforms responsible for targeting sensitive U.S. government networks, including those at NASA, the Federal Reserve, the Senate, and the Justice Department itself.
The platforms, known as QScan and QTRouter, were operated by the Nanjing Xinjiuwei Network Technology Company, a firm based in China whose clients included the Ministry of State Security and the People's Liberation Army, according to court documents. The action disrupts a campaign that has compromised or attempted to compromise critical infrastructure and sensitive networks in the United States and abroad since at least 2018.
An affidavit filed in federal court in California identified several victims of successful intrusions, including three unnamed Energy Department laboratories, the National Institutes of Health, an unnamed Health and Human Services agency, and a U.S. security device manufacturer. The hackers also breached U.S. Senate systems this year. An attempted intrusion at NASA occurred in August 2019, when the group sought to exploit a known vulnerability in a virtual private network.
Other targets included networks operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The level of access gained varied across the incidents.
Attorney General Todd Blanche stated that federal law enforcement had investigated and disabled the malicious software as part of ongoing efforts to counter state-sponsored cyber threats from China. The Chinese Embassy in Washington responded that Beijing opposes all forms of cyberattacks, consistent with its standard denials of such allegations.
The seizure marks the latest in a series of U.S. actions against Chinese cyber operations. The platforms facilitated scanning for vulnerabilities and routing attacks to obscure their origins, according to the Justice Department.
Comments
No comments yet. Be the first to share your thoughts.