
The FBI has taken down the infrastructure of a Chinese state-linked botnet that spent years quietly tunneling through some of the most sensitive computer systems in the United States. According to TechCrunch, federal prosecutors seized a series of domains used to coordinate the operation, effectively cutting off the botnet’s ability to communicate with its command and control servers.
The Justice Department identified the group behind the attacks as QTFY, a hacking outfit run by a Chinese company called Nanjing Xinjiuwei Network Tech. Prosecutors say the company built and maintained a botnet made up of thousands of compromised internet-connected devices, which it then rented out to customers, including hackers working directly for China’s Ministry of State Security. The botnet’s core purpose was obfuscation: routing malicious traffic through ordinary-looking devices to make it harder for defenders to trace attacks back to their source.
The list of targets is long and serious. The attacks date back to 2018 and hit NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was reportedly targeted as recently as 2026. The NSA issued a separate advisory noting that while hackers had scanned Senate networks, they did not successfully break in. That’s a meaningful distinction, but it doesn’t make the access attempts any less alarming.
What makes this operation particularly notable is how it was structured. QTFY wasn’t just a tool used by one government agency. It operated more like a contractor, offering hacking services to Chinese government clients who needed cover for their operations. That model, using a private company as a cutout for state-sponsored intrusions, is exactly the kind of arrangement that makes attribution difficult and legal accountability rare.
Network infrastructure company Lumen also played a role in exposing the operation. The company said in a blog post that it had spent roughly a year tracking the group’s activity, observing targeted scans of government agencies, defense contractors, and aerospace organizations. Lumen shared that threat intelligence with the FBI, which contributed to the eventual domain seizures.
The Justice Department said the seized domains were hardcoded into the botnet’s own code, meaning they weren’t optional routing points. They were essential to how the botnet functioned. Losing them, according to prosecutors, rendered the entire botnet and its command infrastructure inoperable. That’s a bigger win than simply blocking one attack. It dismantles the communication backbone the operators depended on.
Still, context matters here. Domain seizures are a well-established FBI tactic, and while they are disruptive, they are rarely permanent. Operators with enough resources can rebuild infrastructure, shift to new domains, or restructure how their malware communicates. The more important question is whether any of the individuals running Nanjing Xinjiuwei will face legal consequences, and given that they are almost certainly operating from within China, that outcome seems unlikely.
For everyday users, the broader takeaway is this: the compromised devices that made up this botnet were not government systems. They were ordinary internet-connected devices, the kind sitting in homes and small offices everywhere. That’s how these operations work. Your router or security camera doesn’t need to be a high-value target to become a tool in someone else’s attack. Keeping devices updated and replacing hardware that no longer receives security patches is not optional hygiene. It’s part of how these botnets get built in the first place.