China-Supported Botnet Seized: FBI Halts Espionage on Fed and NASA

By: cryptonomist.ch|2026/08/26 17:35:45

A cyber attack lasting 8 years, capable of targeting the Federal Reserve, NASA, and even the United States Senate, has been halted thanks to a technical operation that was both simple and decisive. The FBI and the Department of Justice announced on Wednesday the seizure of a series of internet domains that supported a vast network of compromised devices, used for years by hackers linked to Beijing to infiltrate sensitive American targets. The seizure of the China-supported botnet comes after an investigation that also involved telecommunications giant Lumen, marking one of the most significant blows dealt so far against the hacker infrastructure linked to the Chinese government.

Summary

  • Key points
  • The seizure of domains that blocked the Chinese botnet
  • Who is behind QTFY and Nanjing Xinjiuwei Network Tech
  • The targets hit: from NASA to the US Senate
    • Why the duration of the operation matters
  • The role of Lumen and implications for US-China cybersecurity
  • FAQ
    • What did the FBI seize related to the Chinese botnet?
    • Who managed the botnet used for these cyber attacks?
    • Which US government entities were targeted by the botnet?
    • How recent are the attacks on US government systems?

Key points

  • The FBI seized the domains used by the hacking platforms QScan and QTRouter, rendering them inoperable.
  • The two platforms were managed by the Chinese group QTFY, employed by Nanjing Xinjiuwei Network Technology Company.
  • Among QTFY's clients are the Chinese Ministry of State Security and the People's Liberation Army.
  • The victims include NASA, the Federal Reserve, the Department of Justice, the US Senate, and other federal agencies, with intrusions dating back to at least 2018 and continuing until 2026.

The seizure of domains that blocked the Chinese botnet

The seizure of the domains rendered both QScan and QTRouter, the two hacking platforms at the center of the investigation, inoperable. According to court documents made public in the federal court for the Southern District of California, these internet addresses were directly encoded in the malware of the two platforms: without them, the network could no longer communicate with its command and control servers. This technical detail explains why the operation had such an immediate impact: it was not about physically dismantling thousands of compromised devices around the world, but about cutting the thread that kept them connected to the operational center.

The Department of Justice clarified that the platforms were used to target not only critical US infrastructure but also networks managed by hospitals, telecommunications providers, energy companies, financial institutions, and defense contractors. A scope that goes well beyond the government agencies mentioned in the headlines, indicating the extent of the strategic objective behind this offensive infrastructure.

Who is behind QTFY and Nanjing Xinjiuwei Network Tech

Behind the operation is a group identified by investigators as QTFY, described in documents as sponsored by the Chinese state. It is believed to be managed by the company Nanjing Xinjiuwei Network Tech, based in China, which, according to court documents, created and maintained the hacking platforms. QTFY, according to the Department of Justice, offered paid intrusion services to clients that included directly the Ministry of State Security of the People's Republic of China and the People's Liberation Army.

The two platforms functioned as obfuscation networks: they hid the malicious traffic generated by hackers behind thousands of compromised internet-connected devices, making it much more difficult for security teams to trace the real origin of the attacks. This is the same mechanism behind many state-sponsored digital espionage campaigns, where technical anonymity becomes the main shield to operate undisturbed for years.

Targets Hit: From NASA to the US Senate

The list of confirmed victims illustrates the breadth of the campaign. The intrusions date back at least to 2018 and involved NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, and the National Institutes of Health. The most recent case, and perhaps the most concerning, involves the US Senate, whose computer systems are reported to have been compromised until 2026, according to the affidavit submitted by the government to obtain the domain seizure order.

The Department of Justice did not provide details on the extent of the damage suffered by these agencies nor on the precise nature of the information stolen. This silence on the actual contents of the intrusions raises a central question: how long and to what depth have QTFY operators had access to systems that hold data on monetary policy, space research, and national security.

Why the Duration of the Operation Matters

The fact that such an infrastructure has remained active from 2018 until 2026 says a lot about the resilience of Chinese obfuscation networks and the difficulty for Western security agencies to timely identify patterns of anomalous traffic generated by thousands of compromised devices scattered around the world. It is not a single isolated attack, but a persistent infrastructure designed to remain operational over time, changing targets and adapting to countermeasures.

The Role of Lumen and Implications for US-China Cybersecurity

A decisive contribution to the investigation came from Lumen, the telecommunications giant, which stated that it had observed hackers for about a year as they profiled and targeted government agencies, defense, and aerospace sectors, subsequently sharing the collected information with the FBI. This type of collaboration between private network operators and federal agencies has become an increasingly central tool in countering state-sponsored digital espionage campaigns, as it is often the large providers that intercept suspicious traffic flows first.

The Attorney General Todd Blanche commented on the operation, stating that malicious hackers supported by foreign states and directed against American critical infrastructure "will be stopped and prosecuted," describing the operation as the latest in a series of technical interventions aimed at dismantling indiscriminate hacking activities sponsored by the People's Republic of China. The announcement comes just over a month after another China-related case: the 38-month prison sentence of John Harold Rogers, a former senior advisor to the Federal Reserve Board, who was convicted of making false statements to federal investigators for sharing confidential information on monetary policy with Chinese intelligence operatives, although he was acquitted of the more serious charge of economic espionage.

Taken as a whole, the picture that emerges shows how the seizure of domains is not an isolated incident, but part of a growing pressure from American authorities on multiple fronts of Chinese activity in the United States: from hacking networks as infrastructure to individual persons accused of acting as intermediaries with Beijing's intelligence. It remains to be seen how quickly QTFY or similar groups can rebuild an equivalent infrastructure, and how much this move can effectively delay operations that have gone undetected for years.

-- Price

--
--
--

FAQ

What did the FBI seize related to the Chinese botnet?

The FBI seized the internet domains used by the Chinese botnet to coordinate cyberattacks, rendering the network inoperable.

Who managed the botnet used for these cyberattacks?

The botnet was created and managed by the Chinese company Nanjing Xinjiuwei Network Tech, under the QTFY group.

Which US government entities were targeted by the botnet?

Targets included NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, as well as the United States Senate.

How recent are the attacks on US government systems?

Computers in the US Senate were breached until 2026, while the botnet had been active since at least 2018.

Content created with the assistance of artificial intelligence and human editorial review.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com