Tech

FBI seizes domains of Chinese-backed botnet that breached NASA and Senate

The US Justice Department claims the seizure of key domains has rendered a large-scale botnet inoperable, cutting off command and control servers used to target federal agencies and defence contractors since 2018.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
Markets & Finance

The US Federal Bureau of Investigation has seized a series of domains associated with a large-scale botnet allegedly used by China-backed hackers to infiltrate major American government systems. The Justice Department announced on Wednesday that the seizures deny the operators access to their platforms, effectively rendering the botnet and its command and control servers inoperable.

Prosecutors stated that the botnet was run by the Chinese company Nanjing Xinjiuwei Network Tech under the alias QTFY. The network consisted of thousands of compromised internet-connected devices designed to obfuscate malicious traffic, making hacker activity more difficult to detect. According to the Justice Department, QTFY provides computer hacking services to customers, including Chinese government hackers working for the Ministry of State Security.

The cyberattacks date back to 2018 and have affected a range of high-profile targets, including NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The US Senate was compromised as recently as 2026, according to a government affidavit filed earlier this week seeking a court order to seize the botnet’s domains.

The Justice Department explained that the seized domains were hardcoded into the botnet’s code, making them critical for communication and essential operations. By cutting off these specific domains, the FBI aims to disrupt the botnet’s ability to coordinate and launch further attacks against American targets.

Network giant Lumen provided additional context, stating in a blog post that it had observed the hackers profiling and targeting government agencies, the defence and aerospace sectors, and other entities over the past year. Lumen shared this threat intelligence with the FBI to support the investigation and subsequent seizure actions.

While the Justice Department asserts that the botnet is now inoperable, the attribution of the network to the Chinese government remains based on prosecutorial allegations. The specific extent of data exfiltration or damage within the compromised systems has not been detailed in the available source material.

Continue reading

More from Tech

Read next: Tesla sets 10 October reveal for long-delayed second-generation Roadster
Read next: Trump and Johnson reject calls to slow frontier AI development
Read next: AI doomer warnings put Anthropic’s business interests under scrutiny