FBI chief Kash Patel says operation disrupted a global botnet used by Chinese hackers to target US infrastructure
The United States and several other countries frequently condemn what they say is state-backed Chinese hacking activity of governments, militaries and businesses. PHOTO: SCMP
The United States said on Wednesday that it had disrupted a Chinese hacking operation responsible for break-ins at the US Justice Department, NASA, the Federal Reserve, the US Senate and other sensitive government agencies.
In a statement, the Justice Department said it had seized domains used by two hacking platforms, dubbed “QScan” and “QTRouter”, which it said were used as part of the campaign. An affidavit identified the US Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the US and South Korea as being among the hackers’ victims.
The Chinese Embassy in Washington did not immediately return a message seeking comment. Beijing routinely denies responsibility for hacking activity.
Read More: China’s Moonshot in talks with Microsoft, Amazon, Google over K3 revenue sharing, sources say
FBI Director Kash Patel said the operation resulted in the disruption of a “global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure”.
Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.
These tools were used by PRC cyber actors to hide the origin of their attacks.
Thanks to the work of @FBISanDiego ,… https://t.co/4JllIFik0f
— FBI Director Kash Patel (@FBIDirectorKash) August 26, 2026
The Justice Department said that the platforms were run by a China-based firm, the Nanjing Xinjiuwei Network Technology Company, whose clients it said included China’s civilian intelligence agency, the Ministry of State Security and its military, the People’s Liberation Army.
Reuters could not immediately locate contact details for Nanjing Xinjiuwei.
The affidavit said the group’s computer infrastructure had been used to compromise critical infrastructure and other sensitive networks in the US and worldwide since at least 2018.
Experts who follow Chinese cyber activity say that private contractors routinely carry out high-profile intrusions on behalf of various Chinese government agencies.
“Over the last decade, the number of companies offering niche offensive services has exploded,” said Dakota Cary, a China analyst with cybersecurity company SentinelOne.
The United States and several other countries frequently condemn what they say is state-backed Chinese hacking activity of governments, militaries and businesses.
Beijing rejects the allegations.