US authorities have pulled the plug on a sprawling hacking network they say was built and run by a Chinese state-backed group, marking one of the more significant moves yet in Washington’s effort to choke off foreign cyber operations targeting federal agencies. The China-backed botnet seizure disclosed by the Justice Department this week disabled two hacking platforms allegedly used for years to break into some of the most sensitive corners of the US government, including NASA, the Federal Reserve and the Senate itself.
Summary
Key takeaways
- The FBI and Justice Department seized internet domains tied to two hacking platforms known as QScan and QTRouter, used to target US critical infrastructure.
- A Chinese state-sponsored group called QTFY created and ran the platforms, operating under a China-based firm named Nanjing Xinjiuwei Network Technology Company.
- Victims allegedly include NASA, the Federal Reserve, the Department of Justice, the Energy Department, Health and Human Services, the National Institutes of Health, and the US Senate.
- The Senate was compromised as recently as 2026, while the earliest intrusions trace back to 2018.
- Because the seized domains were hardcoded into the malware, the takedown reportedly left the entire network inoperable.
FBI Seizes Chinese State-Backed Botnet Domains
The Justice Department says the seized domains were the backbone of the operation, hardcoded directly into the malware powering QScan and QTRouter. Cutting off that infrastructure, officials said, rendered both hacking platforms and their command-and-control servers inoperable in one stroke.
Court documents unsealed in the US District Court for the Southern District of California describe the platforms as tools built specifically to penetrate American critical infrastructure and other sensitive networks. Because the domains were essential to how the malware communicated with its operators, the seizure amounted to cutting the network’s lifeline rather than simply blocking a few web addresses.
This matters beyond the technical details. When investigators can dismantle command infrastructure this cleanly, it strips a hacking group of years of built-up access in a single legal action, forcing adversaries to rebuild from scratch rather than simply pivot to new servers.
Operation and Attribution of the Botnet
Prosecutors trace the network back to a Chinese company, tying the platforms to a commercial hacking-as-a-service operation rather than a lone actor. According to the unsealed filings, the group known as QTFY created and operated QScan and QTRouter, and QTFY itself was employed by Nanjing Xinjiuwei Network Technology Company, a firm based in China.
The Justice Department alleges QTFY’s paying clients included the People’s Republic of China’s Ministry of State Security and the People’s Liberation Army — a detail that, if accurate, places the operation squarely within Beijing’s broader intelligence apparatus rather than ordinary cybercrime. That distinction is central to why the case is being treated as state-sponsored espionage rather than a criminal hacking ring chasing financial gain.
Targets and Impact of the Cyberattacks
The list of alleged victims spans some of the most sensitive parts of the federal government and private critical infrastructure. Court filings say the intrusions affected NASA, the Federal Reserve, the Department of Justice, the Energy Department, Health and Human Services, and the National Institutes of Health, along with hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
The timeline is what makes this case particularly striking: the earliest documented intrusions date to 2018, while the US Senate was reportedly compromised as recently as 2026, according to the government’s affidavit. That eight-year span suggests a persistent, long-running campaign rather than an isolated breach — a pattern that raises real questions about how long undetected access can linger inside government networks before it’s caught.
Notably, the Justice Department has not detailed the extent of the damage caused by these intrusions, so the scale of data taken or systems affected at any single agency remains undisclosed.
Role of Threat Intelligence and Future Implications
Private-sector threat intelligence played a direct role in exposing the network, with network operator Lumen saying it had spent the past year tracking the hackers as they profiled and targeted government agencies along with the defense and aerospace sectors. Lumen shared that intelligence with the FBI, contributing to the case that ultimately led to the domain seizures.
Attorney General Todd Blanche framed the action as part of a wider pattern of enforcement against Beijing-linked hacking. “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Blanche said in a statement. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
That last phrase — “the latest in a series” — is the part worth paying attention to. It signals that this domain seizure isn’t a one-off action but part of a sustained campaign by US authorities to dismantle Chinese state-linked hacking infrastructure piece by piece. Whether QTFY or Nanjing Xinjiuwei rebuild under new infrastructure, and whether additional legal action follows beyond the seizures, remains to be seen.
FAQ
What did the FBI seize related to the Chinese botnet?
The FBI and Justice Department seized internet domains used by the hacking platforms QScan and QTRouter, which were hardcoded into the malware’s code. The seizures made both platforms inoperable.
Who operated the botnet used for these cyberattacks?
The platforms were created and operated by a Chinese state-sponsored group known as QTFY, which was employed by a China-based firm called Nanjing Xinjiuwei Network Technology Company.
Which US government entities were targeted by the botnet?
Alleged targets include NASA, the Federal Reserve, the Department of Justice, the Energy Department, Health and Human Services, the National Institutes of Health, and the US Senate, along with hospitals, telecom providers, power companies, financial institutions and defense contractors.
How recent were the attacks on US government systems?
According to the government’s affidavit, the intrusions date back to 2018, with the US Senate reportedly compromised as recently as 2026.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

