China-backed hackers targeted Nasa, US senate and critical infrastructure, FBI says
RNA illustration for representation.
New Delhi: China-backed hackers ran a years-long cyberactivity against sensitive US networks, using thousands of compromised devices to hide the real source of their attacks, according to the United States authorities. The FBI and justice department have now seized the domains behind two hacking platforms that were allegedly used in the operation.
The platforms, QScan and QTRouter, were created and operated by a group known as QTFY, which US investigators say worked for China-based Nanjing Xinjiuwei Network Technology Company. Court documents released by the US justice department say the company provided hacking services to clients including China’s ministry of state security and Chinese army.
The hackers allegedly built a network of infected devices to make their attacks harder to trace. According to reports, QScan was used to find and infect vulnerable internet-connected devices, while QTRouter used those hacked systems and other proxy networks to make the attacks appear to come from outside China.
This meant Chinese cyberoperators could attack a target while making it look as if the connection was coming from another country. The FBI said the system could even make malicious traffic appear to come from devices located near the organization being attacked, helping the hackers avoid detection.
The alleged targets included Nasa, the federal reserve, the US department of energy, the justice department, the department of health and human services, the national institutes of health and the US senate. US investigators also found activity involving defence contractors, financial institutions, universities, hospitals, telecommunications companies and power companies, according to court documents and a joint US cybersecurity advisory.
The effort was not limited to recent attacks. The FBI said QTFY’s activity dates back to at least 2018, with investigators finding an unsuccessful attempt to access a Nasa network in 2019 and later intrusions involving US energy department laboratories, NIH and an HHS agency in 2024.
The FBI and justice department targeted the backbone of the operation rather than trying to take down every infected device. The seized domains were built into QScan and QTRouter and were needed for communication and authentication, so taking control of them made the two platforms inoperable.
The US operation is part of a wider operation against Chinese cyber operations. Washington has previously disrupted networks linked to Chinese groups including Volt Typhoon and Flax Typhoon and removed PlugX malware from thousands of infected US computers, according to the Justice Department.
China has rejected the US accusations. A spokesperson for the Chinese embassy in Washington told reporters that Beijing opposes all forms of cyberattacks, while accusing the US of using cybersecurity concerns to smear China and restrict Chinese companies.
The concerns over China’s technology and cyberactivities have also surfaced in other western countries. In Britain, the Royal Navy recently restricted internet access to cameras fitted on K3 Scout surveillance drones after checks found that the devices were sending routine signals to an IP address in China, although the UK defence ministry said there was no evidence that sensitive defence data had been accessed or transmitted.