Technology

FBI Seizes Domains Behind China-Linked Botnet That Hit NASA, the Federal Reserve, and the Senate

Martin HollowayPublished 44m ago5 min readBased on 5 sources
Reading level
FBI Seizes Domains Behind China-Linked Botnet That Hit NASA, the Federal Reserve, and the Senate
source:justice.gov

The FBI has seized a series of domains used to operate a large-scale botnet that coordinated China-backed cyberattacks against American targets, including NASA, the Federal Reserve, and the U.S. Senate. The Justice Department announced the disruption on August 26, 2026, confirming that the action neutralized the botnet's command and control infrastructure — the set of servers and web addresses used to send instructions to compromised devices TechCrunch.

According to the government's affidavit, the botnet was operated by a Chinese company called Nanjing Xinjiuwei Network Tech, which built and maintained a network of thousands of compromised internet-connected devices. The hacking group behind the operation is known as QTFY. Rather than conducting intrusions solely for its own purposes, QTFY offered computer hacking services to customers, including Chinese government hackers working for the Ministry of State Security, giving them access to the botnet's capabilities TechCrunch.

The intrusions enabled by this infrastructure date back to 2018 and hit a broad swath of U.S. institutions. Compromised targets include the Departments of Energy, Justice, and Health and Human Services, as well as hospitals and defense contractors. The U.S. Senate was compromised as recently as 2026, according to the government's affidavit seeking the court order to seize the botnet's domains TechCrunch.

The domain seizures were effective because the domains were hardcoded into the botnet's code, making them critical to its communication and operations. Hardcoding means the web addresses were written directly into the malicious software rather than fetched from a changing list. With those domains taken offline, the command and control servers became inoperable, severing the operators' ability to issue instructions to the compromised device fleet TechCrunch.

Network provider Lumen shared threat intelligence with the FBI after observing the hackers profiling and targeting government agencies, the defense and aerospace sectors, and other entities over the past year. The company's findings supplemented the government's own investigative work, which culminated in the court-authorized seizure operation TechCrunch.

The operational model here is worth examining. QTFY functioned as a kind of infrastructure quartermaster, building and maintaining the botnet while offering access to state-sponsored hackers who needed proxy resources for their intrusions. This is a notable departure from the pattern where state-sponsored groups build their own tooling from end to end. A commercial entity creating attack infrastructure on behalf of Ministry of State Security operators introduces a layer of plausible deniability while also concentrating risk in a single set of domains.

The hardcoded domain dependency that made the botnet effective also made it brittle. By embedding the command and control domains directly in the botnet's code rather than retrieving them dynamically, the operators simplified their deployment at the cost of a single point of failure. Once the FBI obtained the court order and seized those domains, the entire communication chain broke. This is an architectural lesson that has played out across botnet takedowns for well over a decade, and it remains a recurring vulnerability for operators who prioritize speed of deployment over resilience.

The targeting profile, spanning federal civilian agencies, defense contractors, hospitals, and the Senate, aligns with established patterns of state-sponsored espionage campaigns seeking political, military, and economic intelligence. An intrusion campaign running continuously since 2018, with activity as recent as this year, speaks to the persistence of the access and the difficulty defenders face in fully eradicating compromised infrastructure from their environments.

For security teams in the affected sectors, the disruption of QTFY's command and control is an actionable signal. Devices that were part of this botnet are now stranded, unable to reach their controllers, but they remain compromised. Identifying and remediating those endpoints, many of which may be embedded in operational technology or IoT contexts, is the immediate practical task that follows the FBI's seizure.

The broader context here is one of steady maturation in how law enforcement and the private sector confront state-aligned cyber threats. The cooperation between private sector threat intelligence, in this case from Lumen, and federal law enforcement is a model that has developed over the past decade and continues to yield results against sophisticated actors. The domains are seized, the servers are dark, and the compromised devices are waiting to be found.