FBI’s China-backed botnet seizure ends 8-year hack on NASA and Senate

US authorities have pulled the plug on a sprawling hacking network they say was built and run by a Chinese state-backed group, marking one of the more significant moves yet in Washington’s effort to choke off foreign cyber operations targeting federal agencies. The China-backed botnet seizure disclosed by the Justice Department this week disabled two hacking platforms allegedly used for years to break into some of the most sensitive corners of the US government, including NASA, the Federal Reserve and the Senate itself.
Key takeaways
- The FBI and Justice Department seized internet domains tied to two hacking platforms known as QScan and QTRouter, used to target US critical infrastructure.
- A Chinese state-sponsored group called QTFY created and ran the platforms, operating under a China-based firm named Nanjing Xinjiuwei Network Technology Company.
- Victims allegedly include NASA, the Federal Reserve, the Department of Justice, the Energy Department, Health and Human Services, the National Institutes of Health, and the US Senate.
- The Senate was compromised as recently as 2026, while the earliest intrusions trace back to 2018.
- Because the seized domains were hardcoded into the malware, the takedown reportedly left the entire network inoperable.
FBI Seizes Chinese State-Backed Botnet Domains
The Justice Department says the seized domains were the backbone of the operation, hardcoded directly into the malware powering QScan and QTRouter. Cutting off that infrastructure, officials said, rendered both hacking platforms and their command-and-control servers inoperable in one stroke.
… Continue reading the full article at the original source below.

