The botnet was managed by Nanjing Xinjiuwei Network Tech, a Chinese firm that provided sophisticated obfuscation services to hackers associated with the Ministry of State Security. By routing malicious activity through these infected devices, state-sponsored actors successfully infiltrated hospitals, defense contractors, and high-level government departments. The U.S. Senate remained a target as recently as 2026, according to court filings.
FBI dismantles Chinese-linked botnet targeting US federal agencies
Federal agents have seized a network of domains used to orchestrate persistent cyberattacks against American infrastructure, including NASA, the Department of Justice, and the U.S. Senate. The operation targeted the QTFY botnet, a state-sponsored tool designed to mask malicious traffic across thousands of compromised internet-connected devices since 2018.
Because the seized domains were hardcoded into the botnet’s core architecture, the intervention effectively rendered the command and control servers inoperable. Network giant Lumen, which collaborated with the FBI on the investigation, tracked the group’s activity for over a year, observing detailed profiling of aerospace and defense targets. This disruption severs the primary communication channel the group relied upon to maintain its covert presence in American systems.



Comments (0)
No comments yet. Be the first!