The FBI has seized domains tied to a China-backed botnet that coordinated cyberattacks against U.S. targets, including NASA, the Federal Reserve, and multiple federal departments. Prosecutors allege the botnet, operated by the Chinese company Nanjing Xinjiuwei Network Tech, was run by a state-sponsored group called QTFY and used to launch attacks dating back to 2018.
The botnet functioned as an obfuscation network, masking malicious traffic to evade detection. According to the Justice Department, QTFY provided hacking services to Chinese government hackers, including those working for the Ministry of State Security. The most recent breach targeted the U.S. Senate in 2026, as revealed in a court affidavit filed this week.
Network security firm Lumen reported observing the hackers profiling government agencies and defense sectors over the past year. The FBI’s domain seizures rendered the botnet’s command and control servers inoperable, as the domains were hardcoded into its infrastructure.



