US seizes Chinese hacker domains targeting NASA and Fed

Geopolitics Impact 4
โดย InfoQuest·US·Read original
Summary · why it matters

The United States revealed on Wednesday that authorities have disrupted computer system intrusions by a hacker group backed by the Chinese government, stating that NASA, the Federal Reserve, and the U.S. Senate were among the targeted agencies. The U.S. Department of Justice, along with the FBI, announced the seizure of internet domains used in attacks on critical infrastructure and highly sensitive data networks. Court documents unsealed in federal court in California indicated that the domains used as platforms for the intrusions, known as "QScan" and "QTRouter," were operated by a hacker group with Chinese government backing. The group, called "QTFY," was contracted to work for Nanjing Xinjiuwei Network Technology Co., based in China. U.S. Attorney General Todd Blanche stated that the domain seizures were "the latest technical operation in our campaign to disrupt widespread, indiscriminate cyber attacks sponsored by the People's Republic of China." However, the Department of Justice did not disclose details about the damage to targeted agencies, which also included the NIH, the Department of Energy, and the Department of Health and Human Services, and noted that private companies in the U.S. and South Korea were also targeted. The U.S. government said the hacker group was established in 2018, has ties to a technology company that conducts cyber operations for China, and has business relationships with entities under China's Ministry of State Security. The U.S. announcement comes about a month before President Donald Trump is scheduled to meet with Chinese President Xi Jinping at the White House, where artificial intelligence and other advanced technologies are expected to be top agenda items.

Impact on stocks 0

Theme Impact 2

Off-coverage companies 1

Nanjing Xinjiuwei Network Technology Co.Private▼ Negative
Regulationrelevance

US seizes domains operated by hacker group contracted to Nanjing Xinjiuwei, implicating the company in cyber attacks.

Related news

CrowdStrike Named Forrester Wave Leader in Threat Intelligence

CrowdStrike Holdings was named a Leader in The Forrester Wave Q3 2026 report on external threat intelligence services. The Forrester evaluation highlights CrowdStrike's approach to Threat AI as a foundation for next generation security operations. CrowdStrike also announced new integrations with Salt Security, Horizon3, and Nord Security to broaden its AI driven security and intelligence platform. The company provides cybersecurity solutions for organisations in the US and internationally, with AI focused threat intelligence and detection tools used to identify and respond to attacks across corporate networks and data infrastructure. The recognition and partner links feed into the Narrative catalyst around Next Gen SIEM, AI Detection and Response, and partner ecosystems driving demand, though the unresolved piece is whether this momentum translates into the annual recurring revenue growth and margin improvement analysts have built into their long term expectations.
Simply Wall St·2hRead more →

Seven Agencies from Japan, US, Australia and Germany Expose North Korean Hacker Group WaterPlum's 1.7 Billion Yen Cryptocurrency Theft

Seven agencies from Japan, the United States, Australia and Germany — the National Police Agency, the National Cyber Security Center, the US Federal Bureau of Investigation, the US Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, Germany's Federal Intelligence Service and Germany's Federal Office for the Protection of the Constitution — jointly announced on the 18th the details of cryptocurrency theft by the North Korea-linked cyberattack group WaterPlum. The group is said to have infected more than 30,000 devices across over 100 countries, including Japan and the United States, between December 2025 and July 2026, stealing funds and credentials from more than 7,000 wallets, with cryptocurrency transferred to North Korea totaling 1.7 billion yen, equivalent to 10.71 million dollars. The National Police Agency and the FBI believe that WaterPlum's attackers and some North Korean IT workers operate under the 313th General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea Central Committee. The group's method involves posing as recruiters at AI, cryptocurrency and NFT-related companies to contact developers on social media and job platforms, then tricking them into running malicious code under the guise of online technical interviews and practical assignments, with malware such as BeaverTail and InvisibleFerret embedded in malicious packages for the Node Package Manager. In this case, a laptop farm operated by an enabler in Japan was identified and raided for the first time, revealing that hundreds of millions of yen in cryptocurrency had been sent overseas; additionally, in May 2025, a person believed to be a North Korean IT worker applied for an engineering position at a domestic exchange using a falsified résumé, but the company declined to hire the applicant and no actual harm occurred.
CoinPost·1dRead more →
3

Cisco Launches Splunk AI POD for On-Premises and Air-Gapped Deployments

Cisco Systems pushed Splunk AI deeper into tightly controlled enterprise environments with a new AI POD built for on-premises, private-cloud and air-gapped deployments. The validated setup brings together Cisco infrastructure, Nvidia accelerated computing and Kubernetes-based software, letting enterprises run AI workloads without sending sensitive information outside their own environments. Splunk AI Assistant is available now, while Agent Launchpad is scheduled for later this year, and customers can host selected models from Google, OpenAI and Cisco, with Nvidia models expected to follow. Splunk is also adding Tokenomics, a capability designed to track token spending across AI agents and coding tools while estimating future consumption. Cisco shares climbed nearly 3.3% to $111.255 Thursday, though GuruFocus shows the stock trading 49.36% above its GF Value of $74.49, with product pricing and committed customer volumes still undisclosed.
GuruFocus·1dRead more →