The FBI has seized domains associated with a large-scale botnet, known as QTFY, which was allegedly used to coordinate and launch China-backed cyberattacks against American targets. According to a Justice Department statement on Wednesday, the seizures deny the botnet's operators access to the platforms.
Prosecutors allege the Chinese state-sponsored group, QTFY, was operated by Nanjing Xinjiuwei Network Tech, a Chinese company. The botnet, comprising thousands of compromised internet-connected devices, reportedly served as an obfuscation network to conceal malicious traffic.
The Justice Department stated that QTFY offered computer hacking services to customers, including Chinese government hackers from the Ministry of State Security. The hacks reportedly date back to 2018, affecting entities such as NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The US Senate was reportedly compromised as recently as 2026.
The domain seizures have made the botnet and its command and control servers "inoperable," as the domains were hardcoded into the botnet's code and were critical for its communication and essential operations, the Justice Department said.