AI News Feed
Market watch
World

US Seizes Domains of Chinese Botnet Used in Cyberattacks on NASA, Senate and Federal Agencies

The FBI seized domains tied to a China-backed botnet used in attacks on NASA, the Senate and multiple federal agencies. The botnet, run by Nanjing Xinjiuwei, is now inoperable.

In a statement on Wednesday, the Justice Department said the seizures deny the botnet's operators access to the domains, which were critical for the botnet's communication and essential operations. The botnet was allegedly used by the Chinese government to break into computers across the United States, including systems at hospitals, defense contractors, and several federal government departments.

Prosecutors identified the China state-sponsored group as QTFY, run by a Chinese company called Nanjing Xinjiuwei Network Tech. The company created and operated a botnet of thousands of compromised internet-connected devices. The botnet aimed to serve as obfuscation networks, hiding malicious traffic to make hackers' activity more difficult to detect.

Per the Justice Department, QTFY offers computer hacking services to customers, including Chinese government hackers working for the Ministry of State Security, and allows them to use the botnet. The hacks date back to 2018 and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026, according to the government's affidavit seeking a court order to seize the botnet's domains, filed earlier this week.

The Justice Department said the domain seizures made the botnet and its command and control servers "inoperable," because the domains were hardcoded into the botnet's code and were essential for its communication and operations. Network giant Lumen said in a blog post that it had observed hackers profiling and targeting government agencies, the defense and aerospace sectors, and others for the past year, and shared threat intelligence with the FBI.