The United States has uncovered a Chinese hacker factory that has been infiltrating NASA, the Senate and the Federal Reserve for years

Programming

The US Department of Justice announced the seizure of the domains of two hacker platforms — QScan and QTRouter — through which attackers for eight years in a row tried to penetrate the most sensitive networks of the country: from NASA and the Federal Reserve System to the Senate and Ministry of Energy. Behind the sign of a “private company” from Nanjing, according to investigators, were Chinese intelligence, the Ministry of Defense and the People's Liberation Army.

Eight years of quiet hunting

The story did not start yesterday. According to the case materials, the first attempts to hack American critical infrastructure have been recorded since 2018 — that is, the attackers acted methodically and without haste, probing the perimeter for years. In 2019, for example, they unsuccessfully tried to access the NASA network through a hole in the VPN — it didn’t work, but this was far from the only attempt, notes xrust.

Further — more and more effective. In May 2024, hackers reached the data of defense contractors, financial institutions and universities. In September of the same year — up to three laboratories of the Ministry of Energy, the National Institutes of Health, another department within the Ministry of Health and a manufacturer of safety equipment. And in March 2026 — already this year — the group scanned the networks of the US Senate and one of the American hospitals for vulnerabilities.

Who held the switch

class=»notranslate»>__GTAG5__ According to the Ministry of Justice, the infrastructure of the attacks was managed by the Nanjing company Nanjing Xinjiuwei Network Technology. Formally, it’s an ordinary technology business. In fact, according to American investigators, the list of clients included the Chinese Ministry of State Security, civilian intelligence and the People's Liberation Army. That is, we are faced with the classic model of “hackers for hire”: the state does not get its hands dirty directly, but buys the necessary competencies from a private contractor — fortunately, in China, such a market has grown significantly over the past decade.

It was not possible to get a comment from the company itself — the request was sent after the end of the working day, there was no response.

Beijing turns on the familiar record

The reaction of the Chinese side is predictable to the letter. A representative of the Chinese Embassy in Washington said that he does not know the details of the case, but the Chinese government is, in principle, against any cyber attacks and fights them according to the law. Another representative went further and accused the Americans of using the topic of cybersecurity to “smear” China, and at the same time expanding the concept of national security as a reason to put pressure on Chinese companies.

The formula is familiar: the accusations are rejected, and in the end the party that brought the accusations turns out to be guilty.

Not the first and clearly not the last episode

For those who follow the topic, this story fits into the already familiar series. In March, the FBI reported to Congress that the networks of several agencies associated with those involved in the bureau's investigations had been hacked, an attack also attributed to China. Previously, hackers associated with the PRC got into the correspondence of House of Representatives committees and reached the networks of large telecom operators. One of the most sensational examples of the same genre is the Salt Typhoon group, for information about which the FBI at one time offered a reward of 10 million dollars.

SentinelOne China analyst Dakota Carey, in a conversation with Reuters, drew attention to a structural thing: the number of private Chinese companies offering specialized hacking services has grown exponentially over the past ten years. In fact, an entire shadow industry has emerged, where the boundaries between a commercial contractor and a government instrument are almost completely erased — and this is what makes such cases so time-consuming to investigate: closing one domain is not difficult, finding the end customer is a completely different task.

The seizure of the QScan and QTRouter domains in this sense should not be perceived as the end of history, but as another round in a game that has been going on since at least 2018 and is unlikely to stop due to a couple of disconnected servers.

Sources:
reuters.com
habr.com
globalsecurity.org

Xrust USA uncovered a Chinese hacker factory that has been infiltrating NASA, the Senate and the Fed for years

Оцените статью
Xrust.com
Добавить комментарий