Wednesday, August 26, 2026
Home TechnologyFBI Seizes China-Backed QTFY Botnet Domains, Disrupts U.S. Government Hacks

FBI Seizes China-Backed QTFY Botnet Domains, Disrupts U.S. Government Hacks

by Kim Stewart
0 comments
FBI Seizes China-Backed QTFY Botnet Domains, Disrupts U.S. Government Hacks

U.S. Seizes Domains Tied to China-Backed Botnet Used in Widespread Cyberattacks

Justice Department and FBI seized domains tied to a China-backed botnet that targeted U.S. hospitals, agencies and companies, crippling its control network.

The Justice Department and FBI announced on Wednesday, August 26, 2026, that they had seized a series of internet domains used by a China-backed botnet to coordinate and launch cyber intrusions against American targets. The operation was designed to deny the botnet’s operators access to their command infrastructure and to disrupt ongoing malicious activity. Authorities said the action renders the domains inoperable because they were hardcoded into the botnet’s control code.

Justice Department and FBI execute domain seizures

Federal prosecutors said the seizures were carried out under court authority after an affidavit and related filings showed the domains were central to the botnet’s command-and-control network. The Justice Department described the takedown as a move to interrupt a long-running platform used to obfuscate and relay malicious traffic. The FBI executed technical measures to redirect domain traffic and prevent the operators from using those addresses to manage compromised devices.

Scope of intrusions includes hospitals, agencies and the Senate

Prosecutors and investigators tied the botnet’s activity to intrusions dating back to 2018 that affected a range of U.S. targets, including hospitals, defense contractors and multiple federal departments. The government’s filings allege incidents involving NASA, the Federal Reserve and the Departments of Energy, Justice, and Health and Human Services. The affidavit also states that the U.S. Senate network was compromised as recently as 2026, underscoring the breadth and persistence of the campaign.

Allegations point to QTFY and a Chinese infrastructure company

Officials named the state-sponsored actor operating the platform as QTFY and identified Nanjing Xinjiuwei Network Tech as the company that developed and managed the botnet. Prosecutors say QTFY rented the network’s obfuscation services to customers that included hackers tied to the Chinese Ministry of State Security. The filings portray the arrangement as a commercialized service offering—sold or leased to support intrusion operations by state-aligned actors.

Technical mechanics of the botnet and why domains mattered

Investigators explained that the compromised devices formed an obfuscation layer that hid attacker traffic and helped maintain persistence inside victim networks. Domains hardcoded in the malware served as the main communication channels between infected devices and their controllers, making those addresses critical to the botnet’s operation. By seizing the domains, authorities say they cut the head off the control network and disrupted the choreography the operators used to stage and mask attacks.

Private sector detection and threat-sharing with law enforcement

Network operator Lumen reported observing activity consistent with profiling and targeting of government, defense and aerospace entities and shared indicators with the FBI before the seizure. Industry partnerships and threat intelligence proved central to tracing the infrastructure back to the alleged operators, according to statements from network security sources. The coordinated public-private response illustrates how commercial monitoring and government legal tools are being combined to respond to state-aligned cyber campaigns.

Legal posture and what comes next in the investigation

The Justice Department’s court filings seek to permanently disrupt the infrastructure and to preserve evidence for potential criminal charges and further civil remedies. Prosecutors say the seized domains will remain under government control while investigators continue to map the botnet’s components and identify affected victims. Officials indicated that the action does not mark the end of the probe and that additional steps, including potential charges and international diplomatic measures, remain under consideration.

The seizure marks one of the more consequential U.S. efforts to dismantle a China-backed botnet that investigators say was used to facilitate state-directed hacking for nearly a decade. While the domain takedown complicates the attackers’ ability to coordinate, cybersecurity experts caution that actors can migrate operations or deploy alternative infrastructure, making sustained monitoring and defensive upgrades essential.

You may also like

Leave a Comment

The Calgary Tribune
The voice of Alberta to the world