The FBI has seized a series of domains linked to a large botnet allegedly used by China-backed hackers to coordinate cyberattacks against targets across the United States.

The US Department of Justice said Wednesday that taking control of the domains has cut the operators off from the platforms used to manage the botnet. Investigators say the network was used to compromise computers at hospitals, defense contractors and multiple US government agencies.

According to prosecutors, the China-linked hacking group, known as QTFY, was operated by Nanjing Xinjiuwei Network Tech, a Chinese company that built and maintained a botnet consisting of thousands of compromised internet-connected devices.

The compromised devices were allegedly used as obfuscation networks, allowing hackers to hide the origin of malicious traffic and make their operations harder for security teams to identify and trace.

The Justice Department alleges that QTFY provided hacking services to customers, including Chinese government hackers working for the Ministry of State Security. Those customers could use the compromised devices within the botnet as part of their cyber operations.

The attacks reportedly stretch back to 2018 and have targeted major US institutions, including NASA, the Federal Reserve and the Departments of Energy, Justice and Health and Human Services. A government affidavit filed this week also indicates that the US Senate was compromised as recently as 2026.

US authorities said the domain seizures effectively made the botnet and its command-and-control infrastructure inoperable. The domains were hardcoded into the botnet’s software and played an important role in allowing compromised devices to communicate with the attackers’ infrastructure.


Buy ExpressVPN with PayPal or Credit Card
READ
More Than 9,300 Exposed AWS Keys Still Active, Researchers Warn

Network security company Lumen said it had been tracking the activity for the past year and observed the hackers profiling and targeting government agencies, defense and aerospace organizations and other sectors. The company also shared threat intelligence related to the activity with the FBI.

Advertisement