The US Department of Justice announced the takedown of a large-scale hacking campaign that, according to investigators, was coordinated for years by Chinese threat actors to infiltrate the sensitive networks of US government agencies. As part of the operation, the department seized the domains of two hacking platforms — QScan and QTRouter. According to the case materials, control over them was exercised by the Chinese company Nanjing Xinjiuwei Network Technology, whose clients, investigators claim, included China's civilian intelligence services and the People's Liberation Army. The threat actors, per the DOJ, have been attacking critical infrastructure in the US and abroad since at least 2018.
Multi-Year Campaign Against Government Agencies
The case materials indicate that the hackers systematically targeted entities related to defense, science, and government administration. In August 2019, for instance, the threat actors attempted to infiltrate NASA's networks, an effort that, investigators say, was unsuccessful. A more recent episode dates to March 2026, when hackers failed to gain access to the systems of the US Senate and one American hospital. According to US authorities, it was during this period that the campaign was disrupted at the preparation stage for new attacks.
The Role of Private Contractors
Western experts point out that Beijing is increasingly enlisting private contractors to carry out state cyber operations, allowing it to formally distance itself from official structures. "Over the past decade, the number of companies offering niche offensive services has surged," noted Dakota Carey, an analyst at cybersecurity firm SentinelOne. In her words, it is precisely such "gray" contractors that become a convenient tool for conducting covert offensive campaigns under the guise of commercial activity.
Contradictory Data
The parties' accounts of the case diverge significantly. The US DOJ maintains that this is a long-running campaign in which the attacks were blocked and the infrastructure of the Senate and NASA was not compromised. The Chinese embassy in Washington, by contrast, stated that the government opposes cyberattacks and called the allegations an attempt to "discredit China." It is worth noting separately that other episodes appear in open sources: notably, according to reports based on Financial Times data, Chinese hackers had previously successfully gained access to the email of staff members of US Congressional committees. Thus, one side speaks of a complete failure of the attacks, another of a complete absence of guilt, while a third line of evidence points to individual successful intrusions, making the picture incomplete and contradictory.
Context: Autonomous AI Attacks and Botnets
Experts emphasize that such operations are not isolated. Earlier, OpenAI published a report stating that artificial intelligence independently compromised Hugging Face's infrastructure, bypassing protective restrictions without human involvement. Meanwhile, threat actors regularly exploit vulnerabilities in popular platforms to grow hacking networks: in one attack, hackers turned more than 2,000 WordPress sites into a botnet, creating a large-scale network of thousands of machines for distributing spyware. Against this backdrop, the QScan and QTRouter case looks like part of a broader trend toward the automation and outsourcing of offensive cyber activity.