World

US Seizes China-Linked Hacking Infrastructure That Targeted NASA, the Senate, and the Federal Reserve

Elena MarquezPublished 3d ago6 min readBased on 3 sources
Reading level
US Seizes China-Linked Hacking Infrastructure That Targeted NASA, the Senate, and the Federal Reserve
source:justice.gov

The US Justice Department announced on 26 August 2026 that it had disrupted a China-linked hacking operation that targeted multiple US government bodies, including the Department of Justice itself, NASA, the Federal Reserve, and the US Senate. Working with the FBI, investigators carried out court-authorized domain seizures that took down two complementary hacking platforms known as QScan and QTRouter. These tools had been used to compromise sensitive networks in the US and abroad since at least 2018, according to a court affidavit. (Al Jazeera; Justice Department)

QScan worked as a scanner and infection tool, identifying and compromising thousands of internet-connected devices, including routers and other network equipment. Those compromised devices were then folded into the QTRouter network, which let attackers route their traffic through machines outside China. An attack aimed at a US target could thus appear to originate from another country entirely, or from a device physically close to the intended victim, making it harder for defenders to trace the source or respond effectively. The seized internet domains were hard-coded directly into both the QScan and QTRouter malware, according to the Justice Department. (CNBC)

The platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients, according to the Justice Department, included China's Ministry of State Security (the country's principal civilian intelligence agency) and the People's Liberation Army. Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to requests for comment from Reuters. The FBI's Cyber Division, federal prosecutors in California, and the San Diego field office led the investigation. (Al Jazeera)

The scope of the targeting, as documented in court filings, spans years and touches some of the most sensitive nodes in the US government and research apparatus. Hackers unsuccessfully attempted to access NASA networks in August 2019. In September 2024, they successfully breached networks at three Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, and a US security-device manufacturer. The Federal Reserve, the US Senate, and four unnamed companies in the US and South Korea were also identified as targets. (Al Jazeera)

This operation fits into a broader series of court-authorized actions targeting what Attorney General Todd Blanche described as "indiscriminate hacking activities" sponsored by China. In March 2026, the FBI notified Congress that hackers had penetrated certain agency networks related to people under FBI investigation, with subsequent public reporting attributing the compromise to China. Chinese-linked hackers have also been tied to a compromise of certain US House of Representatives committee networks, as well as multiple major telecommunications companies in recent years. (Al Jazeera)

The broader context here is one of escalating cyber confrontation between Washington and Beijing, conducted largely through infrastructure and proxy actors rather than formal diplomatic channels. The identification of Nanjing Xinjiuwei is notable because it names a specific private-sector company as the operational layer for state clients, a pattern that mirrors prior US identifications of Chinese firms serving as fronts for Ministry of State Security cyber operations. The use of botnet-style infrastructure, compromised consumer devices repurposed as routing relays, is a well-established technique, but the scale and duration alleged in the affidavit, spanning at least eight years, point to a sustained and well-resourced effort. The targeting of the Federal Reserve and the Senate raises the stakes beyond espionage of research networks into the nerve centers of US fiscal policy and legislative oversight.

The domain seizures themselves are a disruption tool, not a permanent remedy. They degrade the attacker's infrastructure and force reconstitution, but they do not necessarily neutralize the actors or their capabilities. QScan and QTRouter are now offline, but the underlying tradecraft, the compromised devices, and the personnel behind them remain. The September 2024 breaches of Department of Energy laboratories, NIH, and HHS confirm that successful intrusions did occur through this infrastructure, and the theft of data from those environments carries potential implications for national security and public health research that extend well beyond the seizure announcement.

The question of attribution is also layered. The Justice Department's affidavit ties the infrastructure to a named company and identifies its clients as MSS and PLA, but the Chinese government has not publicly acknowledged any relationship with Nanjing Xinjiuwei, and the company has not responded to media inquiries. In prior cyber cases involving Chinese state-linked actors, Beijing has consistently denied involvement, framing such accusations as politically motivated. This case is unlikely to alter that pattern.

What is different this time is the specificity of the public disclosure. Court documents identify individual breach events with dates and victim categories, name the operating company, and describe the technical architecture of the platforms in operational detail. That level of disclosure serves multiple purposes: it signals to the Chinese government that the US has detailed visibility into the infrastructure, it provides the private sector with indicators of compromise, and it builds a public record that could support future sanctions or indictments. The reference to four unnamed companies in the US and South Korea suggests the investigation's scope extends beyond what has been publicly charged.

For organizations operating in the sectors identified as targets (energy, health, telecommunications, and legislative infrastructure), the takeaway is operational rather than strategic. The compromised devices that formed the QTRouter network were largely consumer-grade routers and network equipment. Any network that has not audited its edge devices for compromise since at least 2018 remains potentially exposed, and the seizure of the command-and-control domains does not automatically clean infected devices. Incident response teams will need to check for residual QScan or QTRouter artifacts independently of the government action.