The FBI has seized internet domains tied to a large-scale botnet that U.S. prosecutors say was operated by a Chinese state-sponsored hacking group, cutting off the infrastructure used in cyberattacks against American government agencies, hospitals, and defense contractors. The Justice Department announced the seizures on Wednesday, stating that taking control of the domains prevents the operators from using the platforms to coordinate attacks. The botnet is alleged to have been created and run by a Chinese company, Nanjing Xinjiuwei Network Tech, which provided hacking services to customers including government hackers from China’s Ministry of State Security.

The operation, known as QTFY, involved thousands of compromised internet-connected devices that were used as an obfuscation network to hide malicious traffic and make hacker activity harder to detect. According to the Justice Department, the botnet allowed Chinese government hackers to route their operations through these devices, masking their origins. The affidavit filed in court earlier this week seeking authorization for the seizures reportedly details intrusions dating back to 2018, with victims including NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. The U.S. Senate was also compromised as recently as 2026, according to the government’s filing.

The domain seizures rendered the botnet and its command and control servers inoperable, the Justice Department said, because the domains were hardcoded into the botnet’s code and were essential for communication and core operations. By taking the domains, federal authorities effectively cut off the operators’ ability to command the infected devices. The action marks a significant disruption to a network that prosecutors say served Chinese state interests in espionage and other malicious cyber activity targeting U.S. institutions.

Network infrastructure firm Lumen disclosed that it had been monitoring the hackers for the past year, observing them profiling and targeting government agencies as well as the defense and aerospace sectors. The company said it shared threat intelligence with the FBI, which contributed to the investigation leading to the seizures. Lumen’s findings align with the broader pattern of activity described in the Justice Department’s statement, underscoring the persistent nature of the threat posed by the botnet.

The case highlights ongoing U.S. efforts to counter state-sponsored cyber operations, particularly those linked to China, which have increasingly targeted critical infrastructure and federal systems. For American audiences, the seizure represents a concrete step in disrupting foreign espionage campaigns that have reached into the highest levels of government. Federal authorities have not indicated whether additional actions against the botnet’s operators or their customers are forthcoming, and the investigation remains active.

More cybersecurity news from TechManNews.