26 days ago
TechCrunch Aug 26, 2026

US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate

The U.S. Department of Justice and FBI have seized several internet domains tied to a China-backed botnet responsible for cyberattacks on key American institutions. Known as QTFY, this botnet was operated by a Chinese company, Nanjing Xinjiuwei Network Tech, and facilitated government-backed hackers in infiltrating systems at NASA, the Justice Department, the Federal Reserve, and even the U.S. Senate. These attacks, traced back to 2018 and including a Senate breach as recent as 2026, targeted hospitals, defense contractors, and multiple federal departments, underscoring the widespread impact of the botnet’s operations.

The botnet’s infrastructure relied on hardcoded domain names critical for communication and command and control functions, which made these domains essential for its operation. The Justice Department's seizure of these domains has rendered the botnet inoperable by cutting off its servers from control channels, thus disrupting the malicious network’s ability to coordinate attacks. QTFY acted as an obfuscation network, masking hacker activity to evade detection while offering its services to Chinese government entities, including those tied to the Ministry of State Security.

Cybersecurity firm Lumen noted it had been tracking QTFY’s activities for over a year, observing profiling and targeting across multiple sectors such as government agencies, aerospace, and defense. They collaborated closely with the FBI, providing threat intelligence that helped law enforcement agencies build a case for action against the botnet. This successful domain seizure represents a vital step in U.S. efforts to counter foreign state-sponsored cyber threats and protect critical national infrastructure.

The takedown highlights the ongoing cybersecurity challenges posed by sophisticated botnets controlled by state actors, with implications for both government security and private sector operations. It also demonstrates the effectiveness of international cooperation and cyber-defense initiatives in disrupting large-scale digital espionage campaigns. Moving forward, agencies aim to build upon this success to further safeguard sensitive networks from similar threats.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.