Washington (WDN) – The U.S. government says it has disrupted a long-running cyber operation linked to China-backed actors that targeted sensitive American government agencies and critical infrastructure.
The operation allegedly used two hacking platforms, QScan and QTRouter, to scan networks, exploit vulnerabilities and conceal the origin of malicious traffic. U.S. authorities seized internet infrastructure associated with the platforms, significantly disrupting the network.
According to the FBI and U.S. Justice Department, targets included the Departments of Justice, Energy, and Health and Human Services, NASA, the Federal Reserve, the U.S. Senate and the National Institutes of Health, as well as companies in the United States and South Korea.
The infrastructure had reportedly been active since at least 2018, suggesting a sustained campaign rather than a series of isolated attacks. Investigators say the network also targeted hospitals, telecommunications providers, utilities, financial institutions and defense contractors—raising concerns about the potential impact on national security and essential services.
U.S. authorities identified the network as QTFY and linked the operation to Nanjing Xinjiuwei Network Technology Company, a China-based firm that Washington says has connections to Chinese security and military customers. Beijing has not accepted responsibility for the allegations and has routinely rejected U.S. accusations of state-linked cyber operations.
The scale of the activity was substantial. The FBI said QScan alone conducted more than two million vulnerability scans and exploitation attempts in 2024. Investigators also linked the operation to the exploitation of vulnerabilities in Check Point Quantum Gateway devices and the theft of sensitive information from hundreds of U.S. organizations.
The U.S. seizure of the platforms’ internet addresses is intended to cripple the attackers’ ability to communicate with and operate their malicious infrastructure. But officials acknowledge that disrupting one network does not eliminate the broader threat: sophisticated cyber actors can rebuild infrastructure and return under new identities.
The episode highlights the increasingly dangerous nature of cyber conflict. What was once largely associated with stealing information has evolved into a potential threat to power grids, hospitals, telecommunications networks, financial systems and government institutions.
The confrontation also underscores the growing cyber rivalry between Washington and Beijing, with both sides repeatedly accusing the other of digital espionage and malicious cyber activity.
For the United States, the latest operation is therefore more than a successful takedown. It is a reminder that cybersecurity has become a frontline of national security—and that protecting critical infrastructure requires constant vigilance against adversaries capable of operating quietly for years before being exposed.
WardheerNews
