via TechCrunch
FBI Seizes Domains of Chinese Botnet That Targeted NASA, Justice Department, and U.S. Senate
The FBI has seized a network of domains used by a large-scale botnet that coordinated China-backed cyberattacks against American targets, including federal agencies and critical infrastructure. The operation, announced by the U.S. Justice Department on Wednesday, effectively dismantled the botnet's command infrastructure and disrupted ongoing malicious activities.
According to the Justice Department's statement, the seizures render the botnet's command-and-control servers inoperable. The domains were hardcoded into the botnet's code, making them essential for its communication and core operations. By taking control of these domains, the FBI has cut off the operators' access to the platform, hindering their ability to launch further attacks.
The botnet, attributed to a Chinese state-sponsored group known as QTFY, was created and operated by Nanjing Xinjiuwei Network Tech, a Chinese company. The botnet comprised thousands of compromised internet-connected devices, which were used as an obfuscation network to conceal malicious traffic and evade detection. QTFY offered hacking services to its clients, including cyber operatives from China's Ministry of State Security.
Investigators traced the hacking activities back to 2018, with victims including NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was also compromised as recently as 2026, according to a government affidavit filed in support of the seizure.
Lumen Technologies, a network infrastructure provider, played a key role in the investigation. In a blog post, Lumen revealed that it had observed the hackers profiling and targeting government agencies, the defense and aerospace sectors, and other entities over the past year. The company shared threat intelligence with the FBI, which contributed to the successful disruption of the botnet.
This operation marks a significant step in countering state-sponsored cyber threats. As of 2026, the U.S. government continues to strengthen its defenses against such intrusions, emphasizing the importance of public-private partnerships in safeguarding national security.
