FBI Seizes Domains of Chinese Botnet Linked to Hacks of NASA, DOJ, and the U.S. Senate

The FBI has seized domains used by a large-scale botnet that enabled Chinese government-backed hackers to breach multiple U.S. federal agencies, defense contractors, and hospitals, the Justice Department announced on Wednesday, August 26, 2026.

The botnet was operated by a Chinese company called Nanjing Xinjiuwei Network Tech, which ran a hacking-for-hire group known as QTFY. The group provided obfuscation networks — infrastructure designed to disguise malicious traffic and make cyberattacks harder to detect — to customers including hackers working for China’s Ministry of State Security.

The attacks date back to 2018 and targeted NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026, according to a government affidavit filed earlier this week seeking a court order to seize the botnet’s domains.

The Justice Department said the domain seizures rendered the botnet and its command-and-control servers “inoperable.” Because the domains were hardcoded into the botnet’s code, seizing them cut off the operators’ ability to communicate with and coordinate the network of thousands of compromised internet-connected devices.

Network company Lumen said in a blog post that it had observed the hackers targeting government agencies and the defense and aerospace sectors for the past year, and had shared threat intelligence with the FBI ahead of the seizures.

The takedown disrupts a cyberattack infrastructure that spanned nearly a decade and reached some of the most sensitive corners of the U.S. government, though it remains unclear whether any of the underlying hackers have been charged or apprehended.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top