US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate

Summarized from techcrunch.com


The U.S. Justice Department, in coordination with the FBI, has seized a series of domains utilized by a large-scale botnet allegedly backed by the Chinese government. According to the Justice Department’s statement, these domain seizures effectively deny the botnet operators access to the platforms necessary for coordinating and launching cyberattacks against American targets. The botnet, attributed to a Chinese company named Nanjing Xinjiuwei Network Tech and operated by a group known as QTFY, was used to compromise computers across the United States, including systems at hospitals, defense contractors, and several federal government departments.

The Justice Department’s affidavit indicates that the hacks, dating back to 2018, have affected prominent entities such as NASA, the Federal Reserve, and various U.S. government departments, with the U.S. Senate being compromised as recently as 2026. The botnet functioned as an obfuscation network, concealing malicious traffic to hinder detection. By seizing the domains hardcoded into the botnet’s code, critical for its communication and operations, the U.S. authorities have rendered the botnet and its command and control servers inoperable. Network provider Lumen corroborated the threat, noting the hackers’ targeting of government agencies and sectors such as defense and aerospace over the past year, and shared relevant threat intelligence with the FBI. Source