US disrupts Chinese cyber espionage targeting Senate and agencies
Developing story first seen 3 hours ago
The US Justice Department says it has disrupted a Chinese state-sponsored cyber espionage operation by seizing two internet domains used to compromise and conceal access to sensitive networks. The action matters because the alleged campaign reportedly reached major US government bodies and critical infrastructure, illustrating the continuing risk posed by long-running state-backed cyber activity.
Prosecutors said the group, identified as QTFY, had operated since at least 2018 and served clients including China’s Ministry of State Security and the People’s Liberation Army. Its QScan platform allegedly infected internet-connected devices, while QTRouter routed activity through them to mask its origin; reported victims included the US Senate, Federal Reserve, NASA, several federal health and energy agencies, and organisations in the US and South Korea.
- US seizes domains linked to alleged Chinese hacking operation.
- Targets reportedly included Senate, NASA and Federal Reserve networks.
- Malware allegedly used infected devices to conceal attackers’ origins.
New here? Start with this
Cyber espionage is the use of digital tools to obtain information from another country’s government, businesses or public bodies without permission. States may use specialist groups to seek intelligence, monitor targets or gain access to systems that could be useful in a future crisis.
US authorities say the activity involved companies and people they link to China’s Ministry of State Security, the country’s civilian intelligence agency, and the People’s Liberation Army, China’s military. China has previously rejected similar US allegations of state-backed hacking.
The reported targets include government institutions, health and energy bodies, and critical infrastructure, meaning services and systems important to everyday life and national security. Such operations can be hard to trace because attackers may use compromised internet-connected devices to hide where their activity began.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Supporters argue that seizing infrastructure allegedly used for state-backed espionage is a proportionate defensive step to protect democratic institutions, public agencies and critical services. If the reported evidence is sound, disrupting domains that help conceal intrusions can limit immediate harm without escalating to broader punitive measures. They see this as part of a necessary effort to uphold national security, deter persistent cyber operations and protect sensitive public data.
The case against
Sceptics argue that public attribution and domain seizures should be subject to especially rigorous evidential and legal scrutiny, because cyber activity is technically complex and accusations between major powers can intensify diplomatic tensions. China may regard the claims as politically motivated or insufficiently substantiated, while others may worry about states asserting wide authority over internet infrastructure. From this perspective, long-term security is better served by transparent evidence, clear international rules and channels that reduce the risk of reciprocal escalation.
Full account
The US Department of Justice says it has disrupted a Chinese state-sponsored cyber espionage operation that it alleges penetrated a range of sensitive American government networks, including those of the US Senate, NASA, the Federal Reserve and the Justice Department itself. Prosecutors said the activity had been under way since at least 2018 and was linked to a group they call QTFY.
The action centred on the seizure of two internet domains associated with services called QScan and QTRouter. According to the authorities, QScan searched for vulnerable internet-connected devices and could help compromise them, while QTRouter provided routing infrastructure intended to conceal the source of cyber operations. The alleged network also made use of commercial proxy services.
US filings identify Nanjing Xinjiuwei Network Technology Company as the alleged operator behind the services, and say its customers included China’s Ministry of State Security and the People’s Liberation Army. The Justice Department also named the Departments of Energy and Health and Human Services, and the National Institutes of Health, among the affected federal bodies, alongside unnamed companies in the United States and South Korea.
Authorities said the infrastructure was used against sectors including energy, telecommunications, healthcare, finance and defence contracting. The disruption removes identified domains and infrastructure, but the reports do not indicate that the wider cyber threat has ended. China and the company named in the reports had not provided an immediate public response in the material supplied.
Where outlets differ
Source 1 stresses the list of alleged breaches and explains the role of compromised consumer internet-connected devices in accessible terms. Source 2 gives more detail on the alleged contractor, its use of both infected-device botnets and commercial proxies, and cites a researcher involved in the operation.
Source 2 explicitly cautions that the affidavit identifies targeted infrastructure sectors without establishing which individual organisations were successfully breached or the extent of any intrusion. Source 1 presents the sector list more broadly as targeted networks.
Source 2 adds that the group had reportedly shifted towards abusing VPN services used by Chinese citizens, whereas Source 1 focuses on QScan and QTRouter’s core functions.
More coverage
Americas Cybersecurity Government Politics Technology World
Read the full article at the source →
Originally published by Daily Mail as “Chilling plot reveals Chinese ‘cyber spies’ hacked top Trump government agencies and the Senate”.