Chinese hackers broke into US Justice Department, NASA, Senate and more, say officials

Chinese hackers broke into US Justice Department, NASA, Senate and more, say officials

Some of the top US government departments and agencies, including NASA , the Federal Reserve, the US Senate and the Justice Department among other agencies, were targeted in a hacking campaign allegedly carried out by Chinese hackers.

The statement said the group’s computer infrastructure had been used to compromise critical infrastructure and other sensitive networks in the US and around the world since at least 2018.

The Justice Department said in a statement that the two hacking platforms, dubbed ‘QScan’ and ‘QtRouter’, were used by a Chinese group named ‘QTFY’. The Justice Department said ‘QTFY’ was operated by a China-based firm, Nanjing Xinjiuwei Network Technology Company, whose clients it said included China’s civilian intelligence agency, the Ministry of State Security, and its military, the People’s Liberation Army.

Experts who track Chinese cyber activity said private contractors routinely carry out high-profile intrusions on behalf of various Chinese government agencies, said a Reuters report. “Over the last decade, the number of companies offering niche offensive services has exploded,” said Dakota Cary, a China analyst with cybersecurity company SentinelOne. We are here to ensure security for the American people and will use every tool we have to keep that promise,” said Attorney General Todd Blanche. The hackers obtained a key used to secure a cloud-based service, allowing them to bypass security measures, remotely access certain Treasury workstations and view documents maintained by department users, according to a letter sent to lawmakers.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China. The attackers compromised third-party cybersecurity provider BeyondTrust and accessed unclassified Treasury documents.