pollar.news
text-only edition
← Back to top stories
Conflicts · · 8 sources

US disrupts Chinese proxy hacking network targeting NASA, Federal Reserve, and Senate

The US Department of Justice seized domains for QScan and QTRouter, two platforms operated by Chinese contractor Nanjing Xinjiuwei to breach federal agencies and critical infrastructure.

Federal takedown of proxy infrastructure

The United States Department of Justice and the Federal Bureau of Investigation seized the internet domains powering two hacking platforms, QScan and QTRouter, which federal prosecutors say were used by Chinese state-sponsored actors to target American government agencies and critical infrastructure. According to court filings and affidavits, the infrastructure was operated by the QTFY group under a Chinese government contractor named Nanjing Xinjiuwei Network Technology Company. The firm provided hacking and proxy relay services to clients including the Ministry of State Security, China's civilian intelligence service, and the People's Liberation Army. US officials stated that the domain seizures rendered both hacking platforms inoperative. Attorney General Todd Blanche characterized the action as part of ongoing federal enforcement against foreign intrusions.

State-sponsored hackers targeting America's critical infrastructure will be stopped and brought to justice. We are here to keep Americans safe and will use every tool available to deliver on that promise.

— Todd Blanche

Scope of government and sector breaches

Court documents reveal that the proxy tools facilitated cyber intrusions and reconnaissance campaigns dating back to at least 2018. Targeted federal entities include the National Aeronautics and Space Administration, the Federal Reserve, the Department of Justice, the US Senate, the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health. Hackers made an unsuccessful attempt to access NASA networks in August 2019, while a breach of limited scope occurred at the Federal Reserve in 2019. In September 2024, hackers successfully breached networks at three Department of Energy laboratories, the NIH, the HHS, and an American security-device manufacturer. The campaign also reached into critical civilian sectors, targeting power companies, telecommunications providers, hospitals, financial institutions, defense contractors, and four unnamed companies in the United States and South Korea.

Timeline of proxy network operations and enforcement
2018Chinese contractor Nanjing Xinjiuwei begins operating QScan and QTRouter platforms
2019-08Hackers launch an unsuccessful attempt to breach NASA networks
2024-09Intrusions breach three Department of Energy laboratories, NIH, and HHS
2026-08-26US Justice Department and FBI seize domains powering QScan and QTRouter
2026-08-27Chinese Foreign Ministry rejects allegations and calls claims politically motivated

Technical mechanics of the proxy network

The disrupted tools functioned together to obscure the geographic origin of cyber intrusions. The QScan platform identified and compromised thousands of internet-connected devices, such as commercial routers and Internet-of-Things hardware. These compromised systems were then aggregated through QTRouter into a distributed proxy botnet. By routing attack traffic through intermediaries in third countries or local devices near the victims, operators disguised connections to make them look domestic rather than originating from China. Cybersecurity researchers from Lumen Technology's Black Lotus Labs and SecurityScorecard assisted federal authorities in the technical analysis.

When an intrusion appears to come from a device down the street from the target instead of from overseas, it buys the operator time and makes attribution slow.

— Richard Hummel

Beijing denial and diplomatic friction

The Chinese government rejected the allegations on Thursday, stating that the claims lacked evidence. Chinese Foreign Ministry spokesperson Lin Jian voiced strong opposition during a press briefing in Beijing, accusing Washington of abusing legal enforcement for political purposes and calling the United States the largest source of hacking and espionage globally. Lin cited prior Chinese reports concerning alleged National Security Agency operations against China's National Time Service Center to argue that Washington conducts cyber sabotage against foreign infrastructure. The domain seizures follow previous accusations involving groups like Volt Typhoon and Salt Typhoon, which targeted US infrastructure and political candidates. Chinese President Xi Jinping is scheduled to visit Washington in September 2026.

Read the full version on pollar.news →

Sources