US Seizes Domains Associated with Chinese Botnet Linked to NASA, DOJ, and Senate Hacking
The FBI has seized multiple domains that were used by a large botnet involved in orchestrating and conducting cyberattacks sponsored by China against U.S. organizations.
According to the Justice Department’s announcement on Wednesday, the seizure of these botnet domains has prevented the operators from accessing their platforms. This botnet was allegedly used by the Chinese government to penetrate computer networks across the United States, targeting specific entities such as hospitals, defense contractors, and various federal agencies.
Prosecutors disclosed that the China-based state-sponsored group responsible for these activities is known as QTFY, which was overseen by a Chinese company called Nanjing Xinjiuwei Network Tech. This firm created and managed a botnet comprised of thousands of compromised internet-connected devices. The botnet was engineered to function as obfuscation networks, masking the malicious hacker traffic to hinder detection efforts.
As per the Justice Department, QTFY offers hacking services to various clients, including hackers from the Chinese government under the Ministry of State Security, facilitating their use of the botnet.
These hacking operations date back to 2018 and have affected institutions such as NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. A notable security breach at the U.S. Senate occurred as recently as 2026, according to an affidavit submitted by the government as part of its effort to obtain a court order to confiscate the botnet domains earlier this week.
The Justice Department emphasized that the domain seizure has rendered the botnet and its command and control servers “inoperable,” given that the domains were hardcoded into the botnet’s structure, playing an essential role in its communication and operational capabilities.
Networking giant Lumen noted in a blog post that it had been tracking hackers who were profiling and targeting government agencies as well as the defense and aerospace sectors over the last year. Lumen shared pertinent threat intelligence with the FBI during this time.

When you make purchases through links in our articles, we may earn a small commission. This does not influence our editorial independence.


