FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate
The FBI seized domains powering QTFY, a China-backed botnet used since 2018 to breach NASA, the Senate, hospitals, defense contractors and US agencies.
Summary
The FBI seized domains supporting QTFY, an alleged Chinese state-sponsored hacking group that compromised US computers from 2018 through 2026. Prosecutors say Nanjing Xinjiuwei Network Tech operated the service through thousands of compromised internet-connected devices, hiding customers’ malicious traffic and providing botnet access to Chinese Ministry of State Security hackers.
Targets included hospitals, defense contractors, NASA, the Federal Reserve, the US Senate, and the Departments of Energy, Justice, and Health and Human Services. A court affidavit filed during the week of August 26, 2026, said the Senate was compromised as recently as 2026. The Justice Department said seizing the hardcoded domains denied operators access and rendered QTFY and its command-and-control servers inoperable. Lumen, which observed targeting of government, defense, aerospace, and other sectors during the previous year, shared threat intelligence with the FBI.
Positives
- FBI seizures rendered QTFY and its command-and-control servers inoperable because the botnet depended on hardcoded domains.
- Thousands of compromised devices lost access to the domains essential for QTFY’s communications and operations.
- Lumen shared intelligence with the FBI after tracking government, defense, aerospace, and other targeting for a year.
Risks & concerns
- QTFY attacks dating to 2018 compromised hospitals, defense contractors, NASA, the Federal Reserve, and four federal departments.
- The US Senate was compromised as recently as 2026, according to a court affidavit filed that August.
- Nanjing Xinjiuwei Network Tech allegedly built QTFY from thousands of compromised internet-connected devices.
- Chinese Ministry of State Security hackers allegedly used QTFY to conceal malicious traffic and make attacks harder to detect.