The FBI has seized a series of domains used by a large-scale botnet to coordinate China-backed cyberattacks against American targets, according to a Justice Department statement Wednesday, cutting off the operators’ access to infrastructure that had been used to breach U.S. federal agencies dating back to 2018.
What the Botnet Did
Prosecutors said the China state-sponsored hacking group, tracked as QTFY, was operated by a Chinese company called Nanjing Xinjiuwei Network Tech, which built and ran a botnet composed of thousands of compromised internet-connected devices. The botnet functioned as an obfuscation network, hiding hackers’ malicious traffic to make it harder to detect and trace.
According to the Justice Department, QTFY offered computer hacking services to paying customers, including hackers working for China’s Ministry of State Security, who could use the botnet’s infrastructure for their own operations.
Who Was Affected
The hacks trace back to 2018 and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. According to a government affidavit filed this week seeking court authorization to seize the domains, the U.S. Senate was compromised as recently as 2026. The botnet was also used to break into computers at hospitals and defense contractors.
Network infrastructure company Lumen said in a blog post that it had observed the hackers profiling and targeting government agencies, along with the defense and aerospace sectors, over the past year, and shared threat intelligence with the FBI that contributed to the investigation.
How the Seizure Works
The Justice Department said the domain seizures rendered the botnet and its command-and-control servers “inoperable.” The seized domains were hardcoded directly into the botnet’s code and were essential for its communication and core operations, meaning removing them effectively disabled the network rather than just disrupting a portion of it.
Why It Matters
This seizure is one of the more significant actions taken against Chinese state-linked hacking infrastructure targeting U.S. government systems, and it adds concrete detail to a broader pattern of concern. U.S. officials have separately warned in recent years that China-linked hackers, tracked under names like Volt Typhoon, have been planting malware inside U.S. critical infrastructure, believed to be positioned for potential activation during a future conflict, including a possible Chinese move against Taiwan. Russia has been linked to similar campaigns against water and energy infrastructure across Europe.
For federal agencies and the contractors that support them, the case underscores that infrastructure compromises tied to nation-state actors can persist for years, in this instance, nearly a decade, before detection and takedown.
What Happens Next
The Justice Department’s affidavit and public statement suggest the investigation into QTFY and its customers remains active. Given the scope of agencies affected, further disclosures about the extent of the compromise, and potential charges against individuals or entities tied to Nanjing Xinjiuwei Network Tech, are plausible as the case develops.
For continuing coverage of state-sponsored cyberattacks and critical infrastructure security, keep following Tech News Reports for ongoing updates.

