Technology

The FBI Just Took Down a Hacker Network That Targeted NASA, the Senate, and the Federal Reserve

Martin HollowayPublished 3w ago4 min readBased on 5 sources
Reading level
The FBI Just Took Down a Hacker Network That Targeted NASA, the Senate, and the Federal Reserve
source:justice.gov

The FBI has seized a series of web domains used to run a large hacker network that carried out China-backed cyberattacks against American targets, including NASA, the Federal Reserve, and the U.S. Senate. The Justice Department announced the disruption on August 26, 2026, confirming that the action shut down the system the hackers used to control thousands of hijacked devices TechCrunch.

A botnet is a network of computers, phones, or other internet-connected devices that hackers have taken over without the owners' knowledge. Once infected, these devices can be controlled remotely and used to carry out attacks. In this case, the botnet was operated by a Chinese company called Nanjing Xinjiuwei Network Tech, which built and maintained a network of thousands of compromised devices. The hacking group behind the operation is known as QTFY TechCrunch.

Rather than conducting intrusions solely for its own purposes, QTFY offered computer hacking services to customers, including Chinese government hackers working for the Ministry of State Security, giving them access to the botnet's capabilities TechCrunch.

The attacks enabled by this setup date back to 2018 and hit a broad swath of U.S. institutions. Compromised targets include the Departments of Energy, Justice, and Health and Human Services, as well as hospitals and defense contractors. The U.S. Senate was compromised as recently as 2026, according to the government's affidavit seeking the court order to seize the botnet's domains TechCrunch.

The domain seizures worked because the web addresses were baked directly into the botnet's software, making them essential to its operation. Think of these domains as the phone numbers the infected devices used to call for instructions. With those numbers taken away, the hackers could no longer send commands to the device fleet TechCrunch.

Network provider Lumen shared threat intelligence with the FBI after observing the hackers profiling and targeting government agencies, the defense and aerospace sectors, and other entities over the past year. The company's findings supplemented the government's own investigative work, which culminated in the court-authorized seizure operation TechCrunch.

The operational model here is worth examining. QTFY functioned as a kind of infrastructure quartermaster, building and maintaining the botnet while offering access to state-sponsored hackers who needed proxy resources for their intrusions. This is a notable departure from the pattern where state-sponsored groups build their own tools from end to end. A commercial entity creating attack infrastructure on behalf of Ministry of State Security operators introduces a layer of plausible deniability while also concentrating risk in a single set of domains.

The same shortcut that made the botnet effective also made it fragile. By writing the web addresses directly into the software rather than using a changeable list, the operators simplified their setup but created a single point of failure. Once the FBI obtained the court order and seized those domains, the entire communication chain broke. This is a lesson that has played out across hacker network takedowns for well over a decade, and it remains a recurring vulnerability for operators who prioritize speed over resilience.

The targeting profile, spanning federal agencies, defense contractors, hospitals, and the Senate, aligns with established patterns of state-sponsored espionage campaigns seeking political, military, and economic intelligence. An intrusion campaign running continuously since 2018, with activity as recent as this year, speaks to the persistence of the access and the difficulty defenders face in fully removing compromised systems from their environments.

For security teams in the affected sectors, the disruption of QTFY's command system is an actionable signal. Devices that were part of this botnet are now stranded, unable to reach their controllers, but they remain compromised. Identifying and cleaning those endpoints, many of which may be embedded in operational technology or IoT contexts, is the immediate practical task that follows the FBI's seizure.

The broader context here is one of steady progress in how law enforcement and the private sector work together against state-linked cyber threats. The cooperation between private sector threat intelligence, in this case from Lumen, and federal law enforcement is a model that has developed over the past decade and continues to produce results against sophisticated actors. The domains are seized, the servers are dark, and the compromised devices are waiting to be found.