Particle.news

U.S. Seizes Domains and Says It Dismantled China‑Linked Hacker Platforms

The action ties two intrusion tools to a Nanjing firm the U.S. says served Chinese state security and military clients and raises legal and diplomatic pressure

Overview

  • The Justice Department said Wednesday that it seized internet domains used by two intrusion platforms named QScan and QTRouter to disrupt a long‑running hacking operation.
  • A court affidavit and DOJ statement identified the operator as Nanjing Xinjiuwei Network Technology Company and said the firm’s clients included Chinese state security organs and the People’s Liberation Army.
  • U.S. officials named outcomes of the campaign dating back to at least 2018 and said the tools were used to target high‑value victims, including NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, HHS and the NIH.
  • The affidavit says the group attempted to exploit a NASA remote‑access flaw in August 2019 and successfully breached systems at three DOE labs, NIH, an HHS agency and a U.S. security‑equipment maker in September 2024.
  • Cybersecurity experts say the case highlights a growing trend of private Chinese firms offering offensive capabilities to state customers and that the DOJ action could prompt further U.S. investigations, sanctions, or diplomatic responses.