SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate
Go
New
Find
Notify
Tools
Reply
  
US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate Login/Join 
Member
Picture of downtownv
posted
The United States Justice Department announced that federal law enforcement disrupted a widespread Chinese state-sponsored cyber espionage operation targeting high-profile federal institutions.
The compromised entities included the Department of Justice, NASA, the Federal Reserve, and the U.S. Senate, alongside several other sensitive government agencies.
As part of the disruption effort, U.S. authorities seized internet domains associated with two specialized hacking platforms dubbed "QScan" and "QTRouter" that were used to facilitate the network breaches.
Officials did not immediately disclose the full scope of exfiltrated data or the precise timeline during which the unauthorized access occurred.
The Chinese Embassy in Washington did not immediately respond to requests for comment, maintaining Beijing's long-standing stance of denying involvement in government-sponsored cyber intrusions.

https://ground.news/article/us...deral-reserve-senate


_________________________
 
Posts: 10211 | Location: 18 miles long, 6 Miles at Sea | Registered: January 22, 2012Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
quote:
The Chinese Embassy in Washington did not immediately respond to requests for comment, maintaining Beijing's long-standing stance of denying involvement in government-sponsored cyber intrusions.



Tell the lie until it becomes the Truth....
 
Posts: 28415 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Oriental Redneck
Picture of 12131
posted Hide Post
Verified from DOJ:

https://www.justice.gov/opa/pr...te-sponsored-hackers

Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

Wednesday, August 26, 2026

For Immediate Release
Office of Public Affairs

The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter. Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” said Attorney General Todd Blanche. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking - and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”

“Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to the national security,” said Assistant Attorney General for National Security John A. Eisenberg. “These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.”

“We’re taking the fight to PRC sponsored cybercriminals to protect the critical services Americans rely on every day,” said U.S. Attorney Adam Gordon for the Southern District of California.

“The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure,” said Special Agent in Charge Mark Remily of the FBI San Diego Field Office. “Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries. We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”

According to court documents, QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. These computer hacking services include QScan and QTRouter, which work in conjunction. QScan scans and automatically infects thousands of “internet-of-things” (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an “obfuscation network” – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.

This disruption announced today is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC. In 2025, the FBI removed PlugX surveillance malware from over 4,000 U.S. computers after they had been infected by the PRC-sponsored hacker group Mustang Panda. In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which the PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government. In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of U.S. and foreign critical infrastructure. Also today, the FBI and National Security Agency published a cybersecurity advisory providing indicators-of-compromise by QTFY based on their analysis of QTFY malicious cyber activity dating back to at least 2018. In addition, Lumen Technologies’ threat intelligence group, Black Lotus Labs, published a description of QTFY’s tactics, techniques, and procedures: www.lumen.com/blog/en-us/the-i...ate-enablement-model.

The FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division investigated this hacking activity and led this disruption effort.


Q






 
Posts: 31309 | Location: TEXAS | Registered: September 04, 2008Reply With QuoteReport This Post
Green grass and
high tides
Picture of old rugged cross
posted Hide Post
I know nothing about this. But with the amounts of young prc illegals that have entered our country in recent years. And probably for decades there is no doubt that there are potentially millions here reporting back to the homeland and doing damage while being here. They should all be sent home at a minimum.



"Practice like you want to play in the game"
 
Posts: 21867 | Registered: September 21, 2005Reply With QuoteReport This Post
Member
Picture of downtownv
posted Hide Post
quote:
Originally posted by old rugged cross:
I know nothing about this. But with the amounts of young prc illegals that have entered our country in recent years. And probably for decades there is no doubt that there are potentially millions here reporting back to the homeland and doing damage while being here. They should all be sent home at a minimum.


Along with all muslims.


_________________________
 
Posts: 10211 | Location: 18 miles long, 6 Miles at Sea | Registered: January 22, 2012Reply With QuoteReport This Post
Optimistic Cynic
Picture of architect
posted Hide Post
The announcement is painfully thin on how it happened, whether all affected agencies fell to the same exploit, and how long it has been going on. Too much to hope for full disclosure, and even less likely, individual notification of compromised data.

I'm on the side of putting together retribution squads to target these miscreants. Knock a few of them off or rendition them, and the hacker community will learn the lesson quickly. All I'm saying is to treat them like the terrorists they are.
 
Posts: 8087 | Location: NoVA | Registered: July 22, 2009Reply With QuoteReport This Post
Shall Not Be Infringed
Picture of nhracecraft
posted Hide Post
quote:
Originally posted by architect:
The announcement is painfully thin on how it happened, whether all affected agencies fell to the same exploit, and how long it has been going on. Too much to hope for full disclosure, and even less likely, individual notification of compromised data.

It's EXTREMELY likely that they don't even know the full extent of the 'hacking' at this point. AND it's possible (likely?) they don't want to disclose the specific details of what they do know anyway, especially considering it involves NASA, Federal Reserve, DOE, DOJ, NIH, US Senate, etc anyway. Not to mention, not all hacking involves personal information, so 'individual notification' may either be either completely unnecessary, or WAY down the road once (if?) it is determined to be warranted.


____________________________________________________________

If Some is Good, and More is Better.....then Too Much, is Just Enough !!
Trump 47....Making America Great Again!
"May Almighty God bless the United States of America" - parabellum 7/26/20
Live Free or Die!
 
Posts: 11092 | Location: New Hampshire | Registered: October 29, 2011Reply With QuoteReport This Post
Wait, what?
Picture of gearhounds
posted Hide Post
Imagine if the USA put the same effort forth to maliciously cyberattack China as they do us. Their country is such a train wreck in so many ways; they could ill afford attacks on their power grid, their shitty high speed trains, their shitty weapons and radar, their system of hydroelectric and irrigation structures to include the Three gorges dam.




“Remember to get vaccinated or a vaccinated person might get sick from a virus they got vaccinated against because you’re not vaccinated.” - author unknown
 
Posts: 16597 | Location: Martinsburg WV | Registered: April 02, 2011Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
Now do Russia's Hackers......
 
Posts: 28415 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Political Cynic
Picture of nhtagmember
posted Hide Post
there are a few sources indicating that the Chinese used the SpaceX AI
 
Posts: 55291 | Location: Tucson Arizona | Registered: January 16, 2002Reply With QuoteReport This Post
  Powered by Social Strata  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate

© SIGforum 2026