US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized a series of domains that were used by a large-scale botnet to coordinate and launch China-backed cyberattacks against American targets.
According to the Justice Department’s statement on Wednesday, the seizures of the botnet’s domains deny the operators access to the platforms. The botnet was allegedly used by the Chinese government to break into computers across the United States, including systems at hospitals, defense contractors, and several federal government departments.
Prosecutors said the China state-sponsored group, known as QTFY, was run by a Chinese company called Nanjing Xinjiuwei Network Tech, which created and operated the botnet of thousands of compromised internet-connected devices. The botnet aimed to serve as obfuscation networks, which hide the malicious traffic of hackers to make their activity more difficult to detect.
Per the Justice Department, QTFY offers computer hacking services to its customers, who include Chinese government hackers working for the Ministry of State Security, and allows them to use the botnet.
The hacks date back to 2018, and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026, according to the government’s affidavit seeking a court order to seize the botnet’s domains filed earlier this week.
The Justice Department said that the domain seizures made the botnet and its command and control servers “inoperable,” as the domains were hardcoded into the botnet’s code, and were critical for the botnet’s communication and essential operations.
Network giant Lumen said in a blog post that it had observed the hackers profiling and targeting government agencies, the defense and aerospace sectors, and others for the past year, and shared threat intelligence with the FBI.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


