China-Linked Hacking: US Seizes QScan and QTRouter Domains

China-linked hacking targeting NASA, Federal Reserve and US agencies was disrupted as authorities seized domains tied to alleged cyber platforms.

Published: August 26, 2026

By Thefoxdaily News Desk

The operation involved two hacking platforms used by a Chinese state-sponsored group to target US critical infrastructure and other sensitive networks.
China-Linked Hacking: US Seizes QScan and QTRouter Domains

The United States says it has disrupted a China-linked cyber operation that allegedly targeted sensitive government networks, including systems associated with NASA, the Federal Reserve, the Justice Department, the Department of Energy and the US Senate.

The US Justice Department said it seized domains connected to two hacking platforms, QScan and QTRouter, which investigators said were used as part of a broader campaign against critical infrastructure and other sensitive networks in the United States and elsewhere.

According to a Justice Department affidavit, the infrastructure behind the operation had been used since at least 2018 to compromise networks. The alleged victims identified in the investigation include several US federal agencies, four unnamed companies in the United States and South Korea, and government-related organisations.

At the centre of the case is Nanjing Xinjiuwei Network Technology Company, a China-based technology firm that US investigators allege provided infrastructure and services used by hackers affiliated with Chinese military and intelligence organisations.

The case highlights a growing challenge for governments trying to defend against state-linked cyberattacks: the people carrying out an intrusion may not work directly for a government agency. Instead, intelligence and military organisations can allegedly rely on private technology companies and specialist contractors to provide the infrastructure, tools and technical expertise needed for sophisticated operations.

What the US says it disrupted

The Justice Department’s action focused on two online platforms known as QScan and QTRouter.

Investigators allege that the platforms were part of a hacking infrastructure used to identify vulnerable systems, conceal the origins of cyber activity and gain access to targeted networks.

The government seized domains associated with the platforms, effectively taking control of infrastructure that investigators said had been used in the campaign.

The action is significant because disrupting the infrastructure behind a cyber operation can sometimes be more effective than focusing only on individual attacks. If investigators can identify servers, domains or other technical components used repeatedly by attackers, taking those assets offline can interfere with ongoing operations and provide information about the wider network.

However, seizing domains does not mean that every threat associated with the suspected operators has disappeared. Sophisticated hacking groups can move infrastructure, register new domains, compromise additional servers or modify their techniques.

The US action should therefore be viewed as an effort to disrupt an identified part of a broader cyber operation rather than proof that Chinese state-linked hacking activity has been eliminated.

Which US agencies were allegedly targeted?

The alleged victims span several areas of the US government, making the operation particularly sensitive.

The Justice Department identified NASA and the Federal Reserve among the organisations targeted. The campaign also allegedly reached the Justice Department itself and the US Senate.

The affidavit additionally identified the Department of Energy, the Department of Health and Human Services and the National Institutes of Health as victims.

Four companies based in the United States and South Korea were also identified in the affidavit, although their names were not disclosed.

The range of organisations involved matters because their networks contain very different types of information. A space agency such as NASA handles sensitive scientific and technological information. The Federal Reserve operates within the US financial system. The Energy Department is responsible for areas that include national laboratories and energy infrastructure, while the Health and Human Services Department and NIH hold highly valuable scientific and health-related information.

That variety suggests that the alleged campaign was not narrowly focused on a single policy issue or industry.

Who is Nanjing Xinjiuwei Network Technology Company?

US investigators identified Nanjing Xinjiuwei Network Technology Company as the China-based company allegedly operating the hacking platforms.

The Justice Department said the company’s clients included China’s Ministry of State Security, the country’s civilian intelligence agency, and the People’s Liberation Army.

The allegation is important because it provides a possible link between commercial cyber capabilities and Chinese government organisations.

Reuters reported that it could not immediately locate contact details for the company. The Chinese Embassy in Washington also did not immediately respond to a request for comment on the allegations.

China has routinely rejected accusations that its government is responsible for hacking operations. The allegations in the US case therefore represent the American government’s assessment and investigative findings, rather than a position accepted by Beijing.

Why private Chinese technology companies matter in cyber operations

One of the most important aspects of the case is the alleged role of a private technology company.

State-sponsored cyber operations are sometimes imagined as attacks carried out entirely by government employees sitting inside intelligence agencies or military headquarters. In practice, the ecosystem can be more complicated.

Cybersecurity researchers have increasingly documented the involvement of private companies and contractors in offensive cyber activity. These organisations can provide specialised services such as vulnerability research, malware development, infrastructure management, network access and other technical capabilities.

Dakota Cary, a China analyst with cybersecurity company SentinelOne, said the number of companies offering specialised offensive cyber services had increased substantially over the past decade.

This model can provide governments with flexibility. A government agency does not necessarily need to develop every hacking capability internally if it can obtain specialised services from companies with the required expertise.

It can also complicate attribution. When an attack passes through commercial infrastructure or involves contractors, investigators must establish the relationship between the technical operator and the government organisation allegedly benefiting from the operation.

How QScan and QTRouter fit into the alleged campaign

The US government’s case identifies QScan and QTRouter as two important pieces of the infrastructure.

Although the available allegations do not establish that every activity associated with these platforms was directed at US government networks, investigators say the infrastructure was used in a wider campaign that targeted critical infrastructure and sensitive systems.

Tools designed to identify vulnerable systems can be particularly valuable to attackers. Before attempting to penetrate a network, an attacker may need to determine which systems are exposed to the internet, what software they are running and whether known weaknesses can be exploited.

Routers and other network devices are also attractive targets because compromising them can help attackers hide their activity, redirect traffic or gain a strategic position from which to access other systems.

The alleged use of these types of platforms illustrates why cybersecurity agencies increasingly focus on the infrastructure surrounding an attack rather than looking only for malicious software installed on a victim’s computer.

The operation allegedly dates back to 2018

The Justice Department affidavit says the computer infrastructure associated with the operation had been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and around the world.

A timeline stretching back years changes the significance of the case. It suggests investigators are dealing with an established cyber infrastructure rather than a recently created operation.

Long-running campaigns can be particularly difficult to detect because attackers have time to change tools, replace compromised systems and adapt to defensive measures.

They may also operate against multiple targets simultaneously, making it difficult for individual organisations to see the full picture. One company might notice suspicious network traffic while another sees unusual login activity, without either realising that both incidents are connected to the same underlying infrastructure.

This is one reason why government-led cyber investigations can be important. Agencies can combine information from multiple victims and identify common technical indicators that would be difficult for an individual organisation to detect on its own.

Why government agencies remain attractive targets

Federal government networks are valuable to state-linked hackers for several reasons.

They can contain sensitive policy information, diplomatic communications, technical research, law-enforcement material and data about government operations.

Even when an attacker cannot immediately obtain classified information, access to an agency’s network can provide intelligence about how that organisation works, what systems it operates and which people or departments are responsible for important decisions.

For agencies such as NASA and the Energy Department, the potential value also extends to scientific and technological information. For financial institutions and agencies associated with the financial system, attackers may be interested in information about economic policy, markets and financial infrastructure.

Government networks are therefore not attractive targets simply because of the data stored on individual computers. They can also provide strategic intelligence about how a country operates.

The Federal Reserve angle raises particular concerns

The alleged targeting of the Federal Reserve is especially notable because the central bank plays a critical role in the US financial system.

The Federal Reserve is responsible for monetary policy, banking supervision and other functions that influence the American economy. Information obtained from its systems could potentially provide intelligence about economic policy or financial institutions, depending on which systems were compromised.

The available allegations do not establish that the attackers obtained monetary policy secrets or caused disruption to the Federal Reserve’s operations. That distinction is important.

Cybersecurity cases often involve attempted access, reconnaissance and network compromise without necessarily resulting in the theft or public disclosure of the most sensitive information associated with a target.

The fact that an organisation was targeted should therefore not automatically be interpreted as evidence that all of its most sensitive information was stolen.

NASA and critical infrastructure make the case broader than espionage

The alleged targeting of NASA and the Department of Energy also places the operation within a broader critical-infrastructure context.

Government agencies and public institutions increasingly depend on interconnected digital systems. That creates opportunities for attackers to move from one compromised system to another or use access to gather information about wider networks.

The US affidavit says the infrastructure associated with the campaign had been used against critical infrastructure and sensitive networks around the world.

That language is significant because cyber threats to critical infrastructure can extend beyond traditional espionage. Depending on the target and level of access, cyberattacks can potentially affect communications, energy systems, transportation, financial services and other essential functions.

There is no indication in the material provided that this particular operation caused a major physical disruption to US infrastructure. The documented issue is the alleged compromise and targeting of sensitive networks.

Why China-linked cyber operations are a major US security concern

Washington and Beijing have been engaged in a long-running dispute over cybersecurity and cyber espionage.

The US government has repeatedly accused Chinese state-linked actors of targeting American government networks, businesses and critical infrastructure. Beijing has generally denied responsibility for such operations and has itself accused the United States of conducting extensive cyber activities.

The latest case fits into that broader strategic competition.

Cyber operations can provide governments with intelligence without the costs and visibility associated with conventional espionage. A successful intrusion can potentially provide access to large quantities of information without requiring a physical presence inside the target country.

At the same time, cyber operations create risks of escalation. Governments may respond to major intrusions through sanctions, criminal prosecutions, infrastructure seizures or diplomatic pressure, turning technical incidents into broader geopolitical disputes.

What the domain seizures mean for the attackers

Seizing the domains used by an alleged hacking operation can disrupt command, control or other services that attackers depend upon.

For investigators, domain seizures can also serve another purpose: preserving evidence and publicly exposing infrastructure that may have been difficult for private companies to identify independently.

But cybercriminal and state-linked groups rarely depend on a single technical asset forever. If operators have sufficient resources, they can establish replacement infrastructure.

That makes disruption one part of a continuing defensive process. Governments and companies still need to identify compromised systems, patch vulnerabilities, reset credentials, monitor networks and share information about emerging threats.

What this case reveals about modern state-sponsored hacking

The most important lesson from the case may be the changing structure of cyber warfare and espionage.

Modern state-linked hacking does not necessarily require a government to build every tool internally. A specialised private company can potentially provide services that would otherwise require a large in-house technical operation.

That creates an ecosystem in which intelligence agencies, military organisations, technology firms and specialist contractors can occupy different roles.

It also makes attribution harder. Investigators have to determine not only which computer conducted an attack but who controlled the infrastructure, who paid for or directed the activity, and which organisation ultimately benefited.

The US allegations against Nanjing Xinjiuwei therefore matter beyond the individual company. They illustrate how governments may use commercial cyber capabilities as part of broader intelligence and security operations.

What happens next?

The US disruption does not necessarily mark the end of the alleged Chinese hacking campaign. The immediate effect is to take identified domains and infrastructure out of operation, while the investigation provides a public account of how American authorities believe the system worked.

The next stage will depend on what investigators can establish about the compromised networks, the individuals and organisations involved, and the relationship between the private company and its alleged government clients.

The case could also increase pressure on US agencies and companies to improve protection of internet-facing infrastructure, network devices and other systems that can be exploited as entry points.

For organisations outside government, the warning is equally relevant. The alleged campaign targeted a range of sensitive networks rather than a single type of institution, demonstrating why cybersecurity cannot be treated as a concern limited to national-security agencies.

The larger cybersecurity challenge for the US

The US government’s action against QScan and QTRouter represents an effort to disrupt the machinery behind a suspected state-linked cyber campaign rather than simply respond to an individual breach.

The alleged targeting of NASA, the Federal Reserve, the Justice Department, the Energy Department, HHS, NIH and the US Senate demonstrates the breadth of interest surrounding sensitive American networks.

But the case also illustrates the limits of any single disruption operation. Taking down domains can interrupt an established infrastructure, yet determined attackers can rebuild. The longer-term defence depends on identifying vulnerabilities, sharing threat intelligence and making it harder for attackers to move from initial access to deeper network penetration.

For Washington, the challenge is therefore twofold: disrupt the infrastructure already identified and prevent the next generation of state-linked cyber operations from finding new routes into sensitive systems.

The latest action sends a clear message that the US is willing to use legal and technical measures against infrastructure it believes is supporting foreign state-sponsored hacking. Whether that deterrence is enough will depend on what happens after the seized domains go dark and whether the operators behind them are able to rebuild elsewhere.

FAQs

  • What did the US disrupt in the China-linked hacking operation?
  • Which US agencies were allegedly targeted by the hackers?
  • What are QScan and QTRouter?
  • Which Chinese company is linked to the alleged hacking operation?
  • How long had the alleged cyber operation been active?
  • Was the Federal Reserve's sensitive information stolen?
  • Does seizing the hacking domains end the cyber threat?
  • Why is the China-linked hacking case significant?

For breaking news and live news updates, like us on Facebook or follow us on Twitter and Instagram. Read more on Latest World on thefoxdaily.com.

COMMENTS 0