Cybersecurity2 mins read

FBI Seizes Domains Tied to China-Backed Botnet Used in U.S. Government Hacks

The FBI seized domains linked to a large-scale botnet allegedly used by China-backed hackers to target U.S. agencies including NASA, the Justice Department, and the Senate.

What Happened

The FBI seized a series of domains used by a large-scale botnet to coordinate and launch China-backed cyberattacks against U.S. targets. According to the Justice Department statement cited by TechCrunch, the seizures were intended to deny the operators access to the platforms. The Justice Department said the action made the botnet and its command-and-control servers “inoperable.”

Who Was Behind the Botnet

Prosecutors said the China state-sponsored group known as QTFY was run by a Chinese company called Nanjing Xinjiuwei Network Tech. The company allegedly created and operated a botnet made up of thousands of compromised internet-connected devices. The botnet was used as an obfuscation network, helping hide malicious hacker traffic and making activity harder to detect.

Targets Named in the Case

The botnet was allegedly used to break into computers across the United States, including systems at hospitals, defense contractors, and federal government departments. TechCrunch reports that affected entities included NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026, according to the government affidavit cited in the article.

Why the Seizure Matters

An FBI seizure notice.
Image credits:TechCrunch / screenshot.rocks

The domains were hardcoded into the botnet’s code, making them critical to the botnet’s communication and operations. By seizing them, authorities disrupted the infrastructure the operators relied on to manage compromised devices. Network giant Lumen said it had observed the hackers profiling and targeting government agencies, defense and aerospace sectors, and other targets over the past year, and shared threat intelligence with the FBI.

Discover More

    Google Gemini logo with cybersecurity-themed illustration
    Gemini Test Breakout

    Gemini reportedly reached real company systems during a flawed security test.

    Google GeminiAI Security
    A macro close-up photograph shows the Google Gemini AI app icon
    Gemini’s AI Hacking Test

    Gemini accessed three companies’ protected systems during cybersecurity testing, according to TechCrunch.

    AICybersecurity
    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping