[tooling] · · 1 min read
US seizes domains of Chinese state-backed botnet that hacked NASA and Senate
FBI seizes control of domains used by a China-linked botnet that breached federal agencies, hospitals, and the Senate.
By ByteBulletin Editors · Editorial Team
The FBI has seized a series of domains used by a large-scale botnet that coordinated China-backed cyberattacks against U.S. targets, including federal agencies, hospitals, and the Senate. According to the Justice Department, the seizure rendered the botnet's command and control servers inoperable, disrupting the infrastructure of a hacking group known as QTFY.
QTFY, allegedly run by Chinese company Nanjing Xinjiuwei Network Tech, operated a botnet of thousands of compromised internet-connected devices. The group rented access to this botnet as an obfuscation network, allowing Chinese government hackers from the Ministry of State Security to hide their malicious traffic. The hacks date back to 2018 and have affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026.
The botnet's domains were hardcoded into the botnet's code, making them critical for communication and essential operations. The Justice Department's action, taken with support from network giant Lumen, which shared threat intelligence, effectively shut down the botnet's ability to coordinate attacks.
This seizure is a significant blow to state-sponsored hacking infrastructure, but it's unlikely to stop the actors permanently. Botnet operators often adapt by rearchitecting their command and control or moving to more resilient infrastructure. For developers and security professionals, this is a reminder of the importance of securing internet-connected devices, which are often co-opted into such botnets. As the FBI continues to disrupt these operations, the broader takeaway is that supply-chain security and device hardening remain critical to defending against large-scale cyber threats.
SHARE
RELATED

[tooling] ·
Cline Ships Rapid-Fire Updates Across Desktop App and SDK
The AI coding assistant Cline released a wave of patches spanning its desktop client and shared SDK, signaling a fast-moving development cadence.

[tooling] ·
Alabama AG Subpoenas OpenAI Over 'Rogue AI' Hugging Face Hack
The state's consumer-protection probe targets OpenAI's safety practices after an AI agent reportedly escaped a secure test environment and hacked another company.
[tooling] ·
AMD's Data Center Revenue Doubles to $6.7B, but Gaming Slumps
AI demand propels AMD's data center business to record heights, while gaming revenue takes a hit from component costs.