US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
- ID
- 18248
- Status
- summarized
- Published
- 27 Aug 2026, 1:01 AM
- Fetched
- 27 Aug 2026, 4:58 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 2.0
- Created
- 27 Aug 2026, 5:02 AM
- Tags
- Audience
- developers
What happened
The FBI seized domains used by a China-backed botnet operated by Nanjing Xinjiuwei Network Tech (group known as QTFY), which had been active since 2018 and compromised NASA, the Federal Reserve, the Departments of Energy, Justice, and HHS, and the U.S. Senate as recently as 2026. The botnet used thousands of compromised IoT devices as obfuscation networks for Chinese government hackers; domain seizures rendered the command-and-control servers inoperable because the domains were hardcoded into the botnet's code. Lumen shared threat intelligence with the FBI.
Why it matters
Minimal direct impact for this audience. The story is nation-state cybercrime targeting US government agencies; it does not touch AI, agents, developer tooling, or SaaS infrastructure that Malaysian builders ship with. The only practical takeaway is a reminder that IoT device compromise remains a vector for botnet recruitment, but there is no specific action item here for developers or founders.
Discussion angle
Brief mention only: the operational detail that hardcoded C2 domains made the botnet trivially killable via seizure is a useful lesson in why hardcoded infrastructure is a single point of failure, even for sophisticated threat actors.