[tooling] · · 1 min read
US seizes domains of Chinese state-backed botnet that hacked NASA and Senate
FBI seizes control of domains used by a China-linked botnet that breached federal agencies, hospitals, and the Senate.
By ByteBulletin Editor · Editor
The FBI has seized a series of domains used by a large-scale botnet that coordinated China-backed cyberattacks against U.S. targets, including federal agencies, hospitals, and the Senate. According to the Justice Department, the seizure rendered the botnet's command and control servers inoperable, disrupting the infrastructure of a hacking group known as QTFY.
QTFY, allegedly run by Chinese company Nanjing Xinjiuwei Network Tech, operated a botnet of thousands of compromised internet-connected devices. The group rented access to this botnet as an obfuscation network, allowing Chinese government hackers from the Ministry of State Security to hide their malicious traffic. The hacks date back to 2018 and have affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026.
The botnet's domains were hardcoded into the botnet's code, making them critical for communication and essential operations. The Justice Department's action, taken with support from network giant Lumen, which shared threat intelligence, effectively shut down the botnet's ability to coordinate attacks.
This seizure is a significant blow to state-sponsored hacking infrastructure, but it's unlikely to stop the actors permanently. Botnet operators often adapt by rearchitecting their command and control or moving to more resilient infrastructure. For developers and security professionals, this is a reminder of the importance of securing internet-connected devices, which are often co-opted into such botnets. As the FBI continues to disrupt these operations, the broader takeaway is that supply-chain security and device hardening remain critical to defending against large-scale cyber threats.
Get the signal, not the noise.
One short email when it matters. No recaps of recaps.
SHARE
RELATED

[research] ·
Google says Gemini hacking real companies is not misalignment

[research] ·
Anthropic Reveals Four Incidents Where AI Models Hacked External Systems

[models] ·
Google releases Gemini 3.8 Flash, its third Flash model in six weeks

[research] ·
OpenAI delays Astra release to strengthen cybersecurity safeguards

[models] ·
OpenAI Teases 'Astra' Model Capable of Autonomous Zero-Day Exploitation

[tooling] ·
