View English Article
The United States says it has dismantled a China-linked hacking operation that spent years breaking into some of the country’s most sensitive institutions, including the Justice Department, NASA, the Federal Reserve and the Senate. According to an affidavit filed by an FBI agent in support of the seizure of the hacking platforms’ domains, the campaign ran from 2018 through 2026, targeting not only top federal agencies but also hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
The affidavit names the Department of Energy, the Department of Health and Human Services and the National Institutes of Health, along with four unnamed companies in the United States and South Korea, among the confirmed victims. It also states the hackers scanned for vulnerabilities and made unsuccessful attempts to breach the U.S. Senate and an unnamed American hospital as recently as March of this year. The Justice Department identified the operation’s infrastructure as being run by a China-based firm, Nanjing Xinjiuwei Network Technology Company, whose client list, it said, included China’s Ministry of State Security, its civilian intelligence service, and the People’s Liberation Army. The department said it had seized the domains of two hacking platforms used in the campaign, known as QScan and QTRouter.
What stands out is not merely the scale, spanning eight years and reaching into institutions as varied as the central bank, the space agency, hospitals and power companies, but the fact that the campaign’s infrastructure is tied directly to China’s intelligence and military apparatus rather than to private criminal actors operating independently. This confirms, in the form of hard evidence rather than suspicion, that state-directed hacking against core American infrastructure has been sustained and systematic. The inclusion of companies in South Korea among the named victims means this is not simply someone else’s problem across the Pacific. It underscores that Korean firms and institutions sit squarely within the same hacking ecosystem.
Korea needs to treat this as more than a foreign news item and translate it into concrete lessons for its own cybersecurity posture, including tighter security around firms with defense and advanced technology ties, and closer coordination with the United States on tracking and responding to state-linked hacking operations. The Lee Jae-myung government’s relatively soft posture toward China, even as a state-directed hacking campaign has been operating for years and touching Korean companies directly, is not a stance Korea can afford to sustain. The gap between rhetoric about balanced diplomacy and the reality of an active security threat is a gap Korea can no longer justify indulging.
미국이 법무부와 항공우주국, 연방준비제도, 상원까지 수년간 침투당한 중국 배후 해킹 조직을 적발했다고 발표했다. 연방수사국 요원이 해킹 플랫폼 도메인 압수를 뒷받침하기 위해 작성한 진술서에 따르면, 이 해킹 작전은 2018년부터 2026년까지 이어졌으며 연방정부 핵심 기관뿐 아니라 병원, 통신사, 전력회사, 금융기관, 방위산업체까지 겨냥했다.
중국 해커, 어디까지 뚫었나
진술서는 에너지부와 보건복지부, 국립보건원, 그리고 이름이 공개되지 않은 미국과 한국의 기업 4곳을 확인된 피해자로 명시했다. 또한 해커들이 올해 3월 취약점을 스캔하며 미국 상원과 이름이 공개되지 않은 미국 병원에 침투를 시도했으나 실패한 사실도 담겼다. 미 법무부는 이 해킹 인프라를 중국 소재 기업인 난징신주웨이네트워크기술회사가 운영했다고 밝히며, 이 회사의 고객 명단에 중국의 민간 정보기관인 국가안전부와 군인 인민해방군이 포함돼 있다고 설명했다. 법무부는 이번 작전에 쓰인 큐스캔과 큐티라우터라는 두 해킹 플랫폼의 도메인을 압수했다고 밝혔다.
8년, 그리고 국가 정보기관과의 연결고리
주목할 대목은 8년에 걸쳐 중앙은행부터 우주항공기관, 병원, 전력회사까지 폭넓게 뻗친 규모만이 아니라, 이 작전의 인프라가 독립적으로 움직이는 민간 범죄자가 아니라 중국의 정보기관 및 군과 직접 연결돼 있다는 사실이다. 이는 국가 배후의 대미 핵심 인프라 해킹이 의혹 수준이 아니라 구체적 물증으로 확인됐다는 뜻이다. 피해자 명단에 한국 기업까지 포함됐다는 것은 이 사안이 태평양 건너 남의 일이 아니라는 뜻이기도 하다. 한국의 기업과 기관 역시 같은 해킹 생태계 안에 놓여 있다는 점을 분명히 보여준다.
한국이 새겨야 할 안보 함의
한국은 이번 사안을 단순한 외신 소식으로 흘려보내지 말고 국내 사이버보안 태세를 점검하는 구체적 계기로 삼아야 한다. 방위산업과 첨단기술 관련 기업에 대한 보안을 강화하고, 국가 배후 해킹 조직의 추적과 대응에서 미국과의 협력을 더 촘촘히 다져야 한다. 국가 배후 해킹이 수년째 이어지며 한국 기업까지 직접 겨냥한 상황에서도 이재명 정권이 대중국 정책에서 유독 유화적인 태도를 이어가는 것은 더 이상 감당할 수 있는 여유가 아니다. 균형외교라는 수사와 실제 작동 중인 안보 위협 사이의 간극을 이제는 더 이상 방치할 수 없다.
여러분은 어떻게 보십니까? 자유롭게 댓글로 의견을 남겨주세요.
📢 위 글에 공감하셨다면 짧게라도 ‘댓글’을 남겨주세요! 여러분의 한줄이 여론의 흐름을 바꿉니다!
발행인 Peter Kim