VMTech
Discuss a project

FBI Seizure Disrupts QTFY Botnet Used Against US Targets

FBI Seizure Disrupts QTFY Botnet Used Against US Targets

The FBI has seized domains used by the QTFY botnet, disrupting infrastructure that the U.S. Justice Department says supported China-backed cyberattacks against American organizations. The department said the seizures rendered the botnet and its command-and-control servers inoperable because the domains were hardcoded into the botnet’s code and were essential to its communications and operations.

Prosecutors allege that QTFY was operated by Nanjing Xinjiuwei Network Tech, a Chinese company that built and ran a botnet comprising thousands of compromised internet-connected devices. The alleged operation was designed to provide obfuscation networks, concealing malicious hacker traffic and making activity harder for defenders to detect.

Targets included federal agencies and critical sectors

The Justice Department said the intrusions date back to 2018 and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. A government affidavit seeking the seizure order states that the U.S. Senate was compromised as recently as 2026.

The alleged victims also included hospitals and defense contractors. This breadth matters because the botnet was not described simply as a mechanism for infecting devices: it was an intermediary network intended to mask the origin and movement of malicious traffic during intrusions into other systems.

Alleged hacking service for state-linked customers

QTFY allegedly offered computer-hacking services to customers that included Chinese government hackers working for the Ministry of State Security. The Justice Department said those customers could use the botnet, placing the infrastructure at the center of an alleged service model that connected compromised devices with state-linked cyber operations.

Lumen said it had observed the hackers profiling and targeting government agencies, the defense sector, aerospace organizations and other targets over the past year. The network provider shared threat intelligence with the FBI, linking private-sector observation with the law-enforcement action against the domains.

What the domain seizure changes

Seizing hardcoded domains can deny operators a critical means of reaching compromised devices and coordinating command-and-control activity. In this case, the Justice Department said the loss of those domains made the botnet inoperable, directly limiting the infrastructure available to its alleged users.

For businesses and public-sector organizations, the case reinforces the need to investigate signs of traffic routed through compromised devices, not only direct intrusion attempts. Domain disruption can contain an active network, but organisations still need device remediation, network monitoring and timely threat intelligence to reduce exposure to similar obfuscation infrastructure.

#cybersecurity#botnet#threatintelligence#nationstate
Open analytics
On the site 0 views
min read 3 26.08.2026
Instagram

FBI Seizure Disrupts QTFY Botnet Used Against US Targets

Open the post on Instagram ↗