Recent actions by U.S. authorities highlight ongoing concerns over cybersecurity threats posed by foreign actors, particularly amidst rising tensions between nations. In a significant move, the United States has dismantled a hacking operation linked to Chinese interests, designed to infiltrate sensitive government networks, thereby affirming its commitment to protecting national security and critical infrastructure.
The United States has successfully disrupted a hacking operation affiliated with Chinese interests that targeted sensitive government entities, including the U.S. Department of Justice, NASA, the Federal Reserve, and the U.S. Senate. This announcement, made by the Justice Department on Wednesday, detailed the takedown of two crucial hacking platforms, QScan and QTRouter, which had been utilized for cyber intrusions into internet-connected devices since 2018.
According to an affidavit, the operation’s infrastructure has compromised critical networks across the United States and beyond. The hackers previously attempted to infiltrate NASA’s networks in 2019 but were unsuccessful. However, by September 2024, they successfully accessed systems at several Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, along with a U.S. security-device manufacturer, as documented in court proceedings.
Targets of these hacking attempts also included the Federal Reserve, the U.S. Senate, and unnamed companies in the United States and South Korea. The Justice Department identified the operation as being orchestrated by the Nanjing Xinjiuwei Network Technology Company, a firm based in China that purportedly counts among its clients the country’s civilian intelligence agency, the Ministry of State Security, and the military, the People’s Liberation Army.
Despite requests for comment, neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to inquiries from ZezapTV. The QScan platform was reportedly responsible for identifying and infecting thousands of internet-connected devices, including routers and network equipment. These infected devices were then used to create a network via QTRouter, enabling the hackers to obscure their location. Notably, this arrangement allowed attacks to mimic sources from devices in other countries, effectively complicating attribution efforts.
Although the operation does not completely eliminate all hacking activities associated with the group, the seizure of these domains will disrupt their access to crucial platforms. Richard Hummel, a vice president at the cybersecurity firm SecurityScorecard, noted that when intrusions appear to stem from local devices rather than overseas, it complicates the attribution process, allowing hackers to evade detection longer. He stated that taking significant platforms offline severely hampers the operational capabilities of the hackers.
This investigation is part of a larger initiative targeting what Attorney General Todd Blanche described as indiscriminate hacking activities backed by Chinese interests. Spearheaded by the FBI’s Cyber Division, federal prosecutors in California, and the San Diego field office, this operation underscores the U.S. government’s ongoing commitment to safeguarding its cyber frontiers amid evolving threats. Recently, Chinese-linked hacking campaigns have successfully breached a number of sensitive U.S. government and private networks, raising further alarms over cybersecurity vulnerabilities.
#TechnologyNews #WorldNews
