US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
Source Entity
Zack Whittaker

The FBI has dismantled a Chinese-backed botnet operated by Nanjing Xinjiuwei Network Tech that targeted critical U.S. infrastructure. The operation successfully seized domains used to infiltrate federal agencies, defense contractors, and healthcare providers.
FBI Dismantles Chinese-Backed Cyber Espionage Infrastructure
In a significant move to bolster national security, the U.S. Department of Justice and the FBI have successfully seized a series of domains associated with a sophisticated, China-backed botnet. This infrastructure, utilized by a group identified as QTFY and managed by the Chinese firm Nanjing Xinjiuwei Network Tech, served as a conduit for large-scale cyber intrusions. By disabling these domains, federal authorities have effectively severed the command-and-control capabilities of an operation that has long threatened the digital integrity of American institutions.
Targeting the Core of U.S. Infrastructure
The scope of the infiltration was extensive, encompassing a wide array of high-value targets. Court documents reveal that the botnet, which leveraged thousands of compromised internet-connected devices, successfully breached systems within the Federal Reserve, the U.S. Senate, the Department of Justice, NASA, and the Departments of Energy and Health and Human Services. Beyond these federal pillars, the attackers targeted critical sectors including telecommunications providers, power companies, financial institutions, and hospitals, highlighting a clear strategy of mapping and exploiting vulnerabilities within the nation's essential services.
The Mechanics of the Attack: QScan and QTRouter
At the heart of this operation were the hacking platforms known as "QScan" and "QTRouter." These tools were specifically engineered to act as obfuscation networks, designed to mask the origin and nature of the malicious traffic directed at U.S. targets. By routing attacks through a vast web of compromised devices, the perpetrators sought to remain undetected while conducting surveillance and data exfiltration. The seizure of these platforms represents a tactical blow to the group's ability to maintain persistence within these sensitive networks.
Broader Implications for Geopolitical Cybersecurity
The involvement of a state-sponsored entity operating under the guise of a private tech firm, Nanjing Xinjiuwei Network Tech, underscores the evolving nature of modern cyber warfare. This incident serves as a stark reminder of the blurred lines between corporate espionage and state-level cyber aggression. For defense contractors and government agencies, this breach highlights the critical need for robust, proactive threat hunting and the rapid decommissioning of compromised hardware that can be weaponized as part of a botnet.
Future Trends and Defensive Posture
As the U.S. government shifts toward more aggressive disruption campaigns, we can expect a rise in domain seizures and infrastructure takedowns as a primary tool for deterrence. However, the adaptability of groups like QTFY suggests that the threat environment remains highly volatile. The future of cybersecurity will likely rely on deeper public-private partnerships to identify such botnets before they are fully weaponized, ensuring that the digital foundations of national security are shielded from foreign interference.
Multiple Citing Sources