أعلنت الولايات المتحدة إحباط حملة قرصنة إلكترونية واسعة قالت إنها مرتبطة بجهات صينية، واستهدفت أو حاولت اختراق عدد من المؤسسات الحكومية الأمريكية الحساسة، من بينها وزارة العدل ووكالة الفضاء الأمريكية «ناسا» ومجلس الاحتياطي الفيدرالي ومجلس الشيوخ، إلى جانب جهات حكومية وشركات في الولايات المتحدة وكوريا الجنوبية.
وقالت وزارة العدل الأمريكية إنها صادرت نطاقات إلكترونية مرتبطة بمنصتين للقرصنة تحملان اسمي QScan وQTRouter، مشيرة إلى استخدامهما ضمن الحملة الإلكترونية التي استمرت لسنوات واستهدفت شبكات حساسة داخل الولايات المتحدة وخارجها.
وبحسب إفادة قضائية، شملت الجهات التي تعرضت للاستهداف وزارة الطاقة، ووزارة الصحة والخدمات الإنسانية، والمعاهد الوطنية للصحة، إلى جانب أربع شركات لم تُكشف أسماؤها في الولايات المتحدة وكوريا الجنوبية.
منصات قرصنة مرتبطة بشركة صينية
وقالت وزارة العدل إن المنصتين كانتا تديرهما شركة مقرها الصين هي Nanjing Xinjiuwei Network Technology Company، مشيرة إلى أن من بين عملائها أجهزة تابعة للحكومة الصينية، بما في ذلك وزارة أمن الدولة، وهي جهاز الاستخبارات المدنية في الصين، إضافة إلى جيش التحرير الشعبي.
وأوضحت وزارة العدل أن القراصنة استخدموا أدوات طورتها المجموعة لاختراق البنية التحتية الحيوية والشبكات الحساسة في الولايات المتحدة ودول أخرى، وذلك منذ عام 2018 على الأقل.
محاولات استهداف «ناسا» ومؤسسات أمريكية
وتكشف الإفادة القضائية سلسلة من محاولات الاختراق امتدت لسنوات، بعضها نجح وأخرى لم تتمكن من الوصول إلى أهدافها.
ففي أغسطس 2019، حاول القراصنة اختراق شبكات وكالة «ناسا» عبر استغلال ثغرة في شبكة افتراضية خاصة، إلا أن المحاولة لم تنجح.
وفي سبتمبر 2024، تمكنت المجموعة، وفق الإفادة، من تنفيذ عمليات اختراق في ثلاثة مختبرات تابعة لوزارة الطاقة الأمريكية، إضافة إلى المعاهد الوطنية للصحة، وإحدى الوكالات التابعة لوزارة الصحة والخدمات الإنسانية، وشركة أمريكية متخصصة في تصنيع أجهزة أمنية.
كما أصدر مكتب التحقيقات الفيدرالي «FBI» ووكالة الأمن القومي وقيادة الفضاء الإلكتروني الأمريكية تحذيراً مشتركاً تناول عدداً من محاولات القرصنة التي وقعت على مدار السنوات الماضية.
وشملت تلك العمليات، بحسب التحذير، سرقة بيانات من متعاقدين في قطاع الدفاع ومؤسسات مالية وجامعات لم تُكشف أسماؤها في مايو 2024.
محاولات اختراق مجلس الشيوخ في 2026
وفي مارس 2026، رصد القراصنة ثغرات إلكترونية وحاولوا اختراق شبكات تابعة لمجلس الشيوخ الأمريكي ومستشفى أمريكي، إلا أن محاولاتهم لم تنجح، وفقاً للإفادة القضائية.
وقالت «ناسا» إنها لا تعلق على حوادث محددة، بينما أحالت وزارة الصحة والخدمات الإنسانية الأسئلة المتعلقة بالواقعة إلى وزارة العدل.
ولم تقدم وزارة العدل الأمريكية تفاصيل إضافية بشأن الهجمات عند طلبها التعليق.
بكين تنفي الاتهامات
من جانبها، قالت السفارة الصينية في واشنطن إنها ليست على دراية بالتفاصيل المحددة الواردة في بيان وزارة العدل الأمريكية، لكنها أكدت أن الحكومة الصينية «تعارض وتحارب جميع أشكال الهجمات الإلكترونية وفقاً للقانون».
واتهم متحدث باسم السفارة الولايات المتحدة باستخدام قضايا الأمن السيبراني لـ«تشويه سمعة الصين»، كما رفض ما وصفه بتوسيع واشنطن مفهوم الأمن القومي واستخدامه ذريعة لفرض قيود تمييزية على الشركات الصينية.
وأكدت السفارة أن الصين ستعمل على حماية الحقوق والمصالح المشروعة للشركات الصينية.
تصاعد الهجمات المرتبطة بالصين
وتأتي العملية الأمريكية الجديدة في ظل سلسلة من الهجمات الإلكترونية التي نسبت في السنوات الأخيرة إلى جهات مرتبطة بالصين، واستهدفت شبكات حكومية وشركات خاصة أمريكية.
وفي مارس الماضي، أبلغ مكتب التحقيقات الفيدرالي الكونغرس باختراق شبكات تابعة لبعض الوكالات الحكومية المرتبطة بأشخاص كانوا موضع تحقيقات من جانب المكتب، قبل أن تنسب تقارير إعلامية لاحقة الهجوم إلى جهات صينية.
كما ارتبط قراصنة صينيون بعمليات اختراق طالت شبكات بعض لجان مجلس النواب الأمريكي، فضلاً عن عدد من شركات الاتصالات الكبرى خلال السنوات الماضية.
ويرى خبراء يتابعون النشاط السيبراني الصيني أن شركات خاصة أصبحت تلعب دوراً متزايداً في تنفيذ عمليات اختراق متقدمة لصالح جهات حكومية صينية مختلفة.
وقال داكوتا كاري، محلل الشؤون الصينية في شركة الأمن السيبراني «SentinelOne»، إن عدد الشركات التي تقدم خدمات هجومية إلكترونية متخصصة شهد «انفجاراً» خلال العقد الماضي.
وتسلط القضية الضوء مجدداً على تنامي الاعتماد على شركات خاصة لتنفيذ عمليات إلكترونية متقدمة مرتبطة بالدول، وعلى تحول الفضاء السيبراني إلى ساحة رئيسية للصراع الاستخباراتي والإستراتيجي بين واشنطن وبكين.
The United States announced the thwarting of a large-scale cyber hacking campaign that it said was linked to Chinese entities, targeting or attempting to breach a number of sensitive U.S. government institutions, including the Department of Justice, NASA, the Federal Reserve, and the Senate, as well as government entities and companies in the United States and South Korea.
The U.S. Department of Justice stated that it seized electronic domains linked to two hacking platforms named QScan and QTRouter, noting their use in the years-long cyber campaign that targeted sensitive networks both within the United States and abroad.
According to a court filing, the targeted entities included the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health, along with four unnamed companies in the United States and South Korea.
Hacking Platforms Linked to a Chinese Company
The Department of Justice said that the two platforms were operated by a China-based company, Nanjing Xinjiuwei Network Technology Company, indicating that among its clients were agencies of the Chinese government, including the Ministry of State Security, which is China's civilian intelligence agency, as well as the People's Liberation Army.
The Department of Justice explained that the hackers used tools developed by the group to breach critical infrastructure and sensitive networks in the United States and other countries since at least 2018.
Attempts to Target NASA and U.S. Institutions
The court filing reveals a series of hacking attempts that spanned years, some of which were successful while others failed to reach their targets.
In August 2019, the hackers attempted to breach NASA's networks by exploiting a vulnerability in a virtual private network, but the attempt was unsuccessful.
In September 2024, the group managed, according to the filing, to execute breaches in three laboratories belonging to the U.S. Department of Energy, in addition to the National Institutes of Health, one agency under the Department of Health and Human Services, and an American company specializing in manufacturing security devices.
The FBI, the National Security Agency, and U.S. Cyber Command also issued a joint warning addressing several hacking attempts that occurred over the past years.
These operations included, according to the warning, the theft of data from defense contractors, financial institutions, and unnamed universities in May 2024.
Senate Hacking Attempts in 2026
In March 2026, the hackers identified electronic vulnerabilities and attempted to breach networks belonging to the U.S. Senate and an American hospital, but their attempts were unsuccessful, according to the court filing.
NASA stated that it does not comment on specific incidents, while the Department of Health and Human Services referred questions regarding the incident to the Department of Justice.
The U.S. Department of Justice did not provide additional details regarding the attacks when asked for comment.
Beijing Denies the Accusations
For its part, the Chinese embassy in Washington stated that it was not aware of the specific details mentioned in the U.S. Department of Justice's statement, but affirmed that the Chinese government "opposes and fights against all forms of cyber attacks in accordance with the law."
A spokesperson for the embassy accused the United States of using cybersecurity issues to "slander China," and rejected what he described as Washington's expansion of the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies.
The embassy emphasized that China will work to protect the legitimate rights and interests of Chinese companies.
Increase in China-Linked Attacks
The new U.S. operation comes amid a series of cyber attacks that have been attributed in recent years to entities linked to China, targeting government networks and private American companies.
Last March, the FBI informed Congress about breaches of networks belonging to certain government agencies linked to individuals who were under investigation by the bureau, before subsequent media reports attributed the attack to Chinese entities.
Chinese hackers have also been linked to breaches affecting the networks of some committees in the U.S. House of Representatives, as well as several major telecommunications companies over the past years.
Experts monitoring Chinese cyber activity believe that private companies have increasingly played a role in executing advanced hacking operations on behalf of various Chinese government entities.
Dakota Cary, a China affairs analyst at the cybersecurity firm SentinelOne, stated that the number of companies providing specialized offensive cyber services has seen an "explosion" over the past decade.
The case highlights once again the growing reliance on private companies to carry out advanced electronic operations linked to states, and the transformation of cyberspace into a major arena for intelligence and strategic conflict between Washington and Beijing.