US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized domains associated with a large-scale botnet, allegedly operated by a China-backed group known as QTFY, to disrupt cyberattacks against US targets. The Justice Department stated the seizures rendered the botnet inoperable, as its command and control servers relied on these hardcoded domains. This botnet, run by Nanjing Xinjiuwei Network Tech, was used to compromise systems at various US entities, including NASA, the Federal Reserve, and multiple government departments, with hacks dating back to 2018. The U.S. Senate was compromised as recently as 2026, according to government affidavits.
The US government's action against the QTFY botnet, operated by China's Nanjing Xinjiuwei Network Tech, underscores the persistent challenge of state-sponsored cyber warfare. While the immediate impact is on US federal agencies and defense contractors, the broader implication for Asia lies in the escalating cyber arms race and its potential to disrupt regional digital infrastructure. The use of compromised internet-connected devices as obfuscation networks by QTFY reflects a sophisticated approach to cyber espionage that other state actors in Asia may adopt or already employ. For Asian tech companies and governments, this incident highlights the critical need for robust cybersecurity frameworks and international cooperation. The fact that the U.S. Senate was compromised as recently as 2026, as stated in the affidavit, points to the long-term nature of these threats and the continuous evolution of attack vectors. This event serves as a reminder that even advanced economies are vulnerable, urging a re-evaluation of national cybersecurity strategies across Asia to protect critical sectors from similar large-scale, state-backed operations.



