US Department of Justice Disrupts Major Chinese Hacking Operation Targeting NASA, Fed, and Global Infrastructure
ONLINE TEAM
korocamia@naver.com | 2026-08-27 09:26:44
The United States Department of Justice announced on August 26, 2026, that it successfully disrupted a large-scale cyberespionage campaign orchestrated by hackers linked to China. According to Reuters and statements from federal authorities, the sophisticated operation targeted high-profile government institutions, critical infrastructure, and private corporations across the United States and South Korea.
Key Details of the US Department of Justice Announcement
Targeted Institutions: The targeted entities included the US Department of Justice, the National Aeronautics and Space Administration (NASA), the Federal Reserve (Fed), the US Senate, the Department of Energy, the National Institutes of Health (NIH), and various other vital government and public health agencies.
Malicious Infrastructure: Federal authorities seized multiple domains used by two primary hacking platforms named "QScan" and "QTRouter." These platforms infected Internet of Things (IoT) devices to mask the true origins of malicious communication.
State-Sponsored Backing: The platforms were operated by a Chinese entity identified as Nanjing Xinzhuwei Network Technology Co., Ltd. Court documents revealed that the company's clientele included key state security apparatuses, specifically China's Ministry of State Security and the People's Liberation Army.
Timeline and Scope of Cyberattacks
According to court filings, the threat actors utilized customized tools to infiltrate critical infrastructure and networks globally since at least 2018.
August 2019: Hackers targeted Virtual Private Network (VPN) vulnerabilities in an unsuccessful attempt to breach NASA networks.
September 2024: The campaign expanded to compromise three research laboratories under the Department of Energy, the NIH, a health agency affiliate, and an American security equipment manufacturer. Furthermore, the operation extended internationally, impacting a total of four major companies across South Korea and the United States.
March 2026 Disclosures: The Federal Bureau of Investigation (FBI) previously informed Congress that threat actors had penetrated networks associated with specific individuals under FBI investigation. Additional reports linked the same network of hackers to infiltrations of specific committees within the US House of Representatives and multiple major telecommunications firms over recent years.
Expert Insights and International Context
Cybersecurity analysts emphasize that this case highlights a broader, alarming trend in global cyber warfare. Dakota Cary, a China analyst at cybersecurity firm SentinelOne, noted that the number of specialized enterprise-grade cyber-attack service providers has surged exponentially over the past decade, blurring the lines between state actors and commercial hacking contractors.
Despite mounting evidence and international pressure from Western cybersecurity agencies, the Chinese government has consistently denied any involvement in state-sponsored cyberespionage activities. The recent domain seizures and subsequent legal actions by US law enforcement mark a significant blow to the operational capacity of these foreign intelligence-linked threat groups.
WEEKLY HOT
- 1NVIDIA Expands Strategic Partnership with Amazon, Supplying 2 Million Additional AI Chips Amid Surging Global Demand
- 2Kioxia Investment in Iwate & AI Memory Expansion Strategy
- 3Financial Strain: Japan's Major Hike in Foreign Residency and Visa Fees
- 4Far-Right Pre-Election Speed Run in the Occupied Territories: UN Facility Demolitions, Monument Destruction, and Settlement Expansion
- 5FTC Takes Strict Stance Against Coupang's Unprecedented Investigation Refusal
- 6U.S. State Department Imposes Worldwide Pause on Immigrant Visa Interviews for Enhanced Screening Training