The FBI has seized a series of domains that were used by a large-scale botnet to coordinate and launch China-backed cyberattacks against American targets.
According to the Justice Department’s statement on Wednesday, the seizures of the botnet’s domains deny the operators access to the platforms. The botnet was allegedly used by the Chinese government to break into computers across the United States, including systems at hospitals, defense contractors, and several federal government departments.
Prosecutors said the China state-sponsored group, known as QTFY, was run by a Chinese company called Nanjing Xinjiuwei Network Tech, which created and operated the botnet of thousands of compromised internet-connected devices. The botnet aimed to serve as obfuscation networks, which hide the malicious traffic of hackers to make their activity more difficult to detect.
Per the Justice Department, QTFY offers computer hacking services to its customers, who include Chinese government hackers working for the Ministry of State Security, and allows them to use the botnet.
The hacks date back to 2018, and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was compromised as recently as 2026, according to the government’s affidavit seeking a court order to seize the botnet’s domains filed earlier this week.
The Justice Department said that the domain seizures made the botnet and its command and control servers “inoperable,” as the domains were hardcoded into the botnet’s code, and were critical for the botnet’s communication and essential operations.
Network giant Lumen said in a blog post that it had observed the hackers profiling and targeting government agencies, the defense and aerospace sectors, and others for the past year, and shared threat intelligence with the FBI.
Facts Only
* The FBI seized domains used by a large-scale botnet.
* The botnet coordinated and launched China-backed cyberattacks against American targets.
* Seizing the domains denied operators access to the platforms.
* The botnet was allegedly used by the Chinese government to break into computers across the United States, including systems at hospitals, defense contractors, and federal departments.
* The botnet was run by a Chinese company named Nanjing Xinjiuwei Network Tech, which created and operated thousands of compromised devices.
* The botnet functioned as obfuscation networks to hide malicious hacker traffic.
* QTFY allegedly offered computer hacking services to customers, including Chinese government hackers for the Ministry of State Security.
* Hacks dated back to 2018.
* Affected entities include NASA, the Federal Reserve, and Departments of Energy, Justice, and Health and Human Services.
* The U.S. Senate was reportedly compromised as recently as 2026.
* Domain seizures made the botnet and its command and control servers inoperable because the domains were hardcoded into the code.
* Lumen observed hackers targeting government agencies, defense, and aerospace sectors over the past year.
Executive Summary
The FBI seized domains used by a botnet coordinating China-backed cyberattacks targeting American entities. The seizure denied the operators access to these platforms. This botnet was allegedly used by the Chinese government to infiltrate computers across the United States, including systems at hospitals, defense contractors, and federal government departments.
The botnet was reportedly operated by a Chinese company named Nanjing Xinjiuwei Network Tech, which created and managed thousands of compromised internet-connected devices. The network served as obfuscation channels to conceal hacker traffic. The group, known as QTFY, allegedly provided computer hacking services to customers, including Chinese government hackers working for the Ministry of State Security.
The malicious activities began in 2018 and affected organizations such as NASA, the Federal Reserve, and various Departments of the Energy, Justice, and Health and Human Services. The domains were seized because they were hardcoded into the botnet's code, making them critical for communication and operations. Network giant Lumen reported observing hackers targeting government agencies and defense/aerospace sectors over the past year and shared this threat intelligence with the FBI.
Full Take
The narrative describes a state-sponsored infrastructure used for coordinated espionage, relying on large-scale compromise and obfuscation techniques. The critical action is the disruption of command and control via domain seizure, which functionally rendered the malicious infrastructure inoperable. This points to a strategic move by law enforcement targeting the operational backbone rather than just the endpoints.
The pattern reveals a shift in focus from exploiting vulnerabilities to controlling the communication channels necessary for sustained operations. The mention of various high-value targets (NASA, Federal Reserve, government departments) and specific state actors suggests a persistent, long-term intelligence collection strategy woven into seemingly disparate systems. The concept of obfuscation networks illustrates the trade-off between malicious utility and operational security; the necessity of hiding traffic often drives the complexity of the system itself.
The implications suggest that digital sovereignty is challenged not just by direct intrusion but by the control over the communication and coordination layers used by threat actors. When infrastructure like domains is targeted, it reflects a recognition that controlling the flow of information—the 'how' and 'where' of the attack—is as important as the initial breach. The connection drawn between commercial entities (Nanjing Xinjiuwei Network Tech) and state objectives highlights the complex interplay between corporate technology and geopolitical conflict.
What would change one's mind about the role of digital infrastructure in cyber warfare? How can security frameworks account for threats that are intentionally designed to be opaque rather than merely detected? Is the focus on seizing domains sufficient, or does it overlook the broader systemic risk associated with these persistent, layered control mechanisms?
Sentinel — Human
The text reads like a standard report synthesizing information from official government statements and reported observations regarding a cybersecurity incident.
