US Seizes Chinese Botnet Domains Used in Government Cyberattacks
The US government seized domains linked to a China-backed botnet accused of targeting NASA, federal agencies, hospitals and defence firms.
The U.S. Department of Justice and FBI have seized a group of domains used by a China-backed botnet that allegedly supported cyberattacks against American organisations, including government agencies, hospitals and defence contractors.
The Justice Department said the domain seizures disrupted the botnet’s operations by cutting off access to platforms used by its operators. The seized domains were critical to the botnet’s command-and-control infrastructure and were embedded into its code.
QTFY Botnet Linked to China-Based Cyber Operations
According to prosecutors, the China state-sponsored group known as QTFY was operated by Nanjing Xinjiuwei Network Tech, a Chinese company accused of creating and managing a network of thousands of compromised internet-connected devices.
The botnet was used as an obfuscation network, allowing hackers to hide their activity by routing malicious traffic through infected devices. The Justice Department said the service was offered to customers, including Chinese government hackers associated with the Ministry of State Security.
Government officials said the activity dates back to 2018 and involved attempts to target organisations including NASA, the Federal Reserve, and the Departments of Energy, Justice and Health and Human Services.
The U.S. Senate was also targeted as recently as 2026, according to a government affidavit supporting the domain seizure request. The National Security Agency said separately that the hackers scanned Senate networks but did not successfully gain access.
Botnet Infrastructure Used to Hide Malicious Activity
The FBI said the seized domains rendered the botnet and its command-and-control servers inoperable because the infrastructure depended on them to communicate with compromised devices.
A cybersecurity advisory from U.S. agencies described QTFY as part of a broader China-linked malicious infrastructure operation. The advisory detailed the group’s use of compromised systems and infrastructure to support cyber operations.
Lumen said it had tracked activity over the past year, observing attempts to profile and target government agencies, defence and aerospace organisations, and other sectors. The company shared threat intelligence with the FBI as part of the investigation.
The seizure represents a disruption to the infrastructure used by botnet operators, but U.S. officials continue to monitor related cyber threats targeting government and critical infrastructure organisations.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0