The U.S. government has cracked down on a China-linked botnet accused of executing long-running cyberattacks against critical American institutions. Late on August 26, federal authorities seized web domains tied to a botnet operated by Nanjing Xinjiuwei Network Tech — reportedly at the behest of Chinese intelligence agencies.
Breakdown of the Botnet and Its Reach
The botnet, known as QTFY, used thousands of compromised devices across the internet to mask illicit activity. Rather than directly attacking systems, it served as a proxy network: traffic was funneled through these zombie machines to make tracking and attribution more difficult.
Federal filings allege QTFY was used to breach or infiltrate systems at federal bodies including NASA, the Federal Reserve, and Departments of Energy, Justice, Health and Human Services. Most recently, the U.S. Senate was among the targets. These operations are said to have begun in 2018 and have continued up to 2026.
Legal Move and Operational Disruption
The Justice Department, with court approval, seized domains hardcoded into QTFY’s command-and-control infrastructure. These domains were central to the botnet’s operation — once redirected, they rendered core portions of the network unusable.
Separately, network security firm Lumen revealed its role in monitoring QTFY activity. For over a year, Lumen has tracked efforts to profile and attack governmental, aerospace, and defense targets, and provided intelligence to the FBI.
The operation is significant not only for its scale but also attribution. Prosecutors link QTFY with the Chinese Ministry of State Security via its operator, Nanjing Xinjiuwei. According to filings, Xinjiuwei offered hacking services using the botnet, recruiting state actors among its clientele.
Domains were lawfully seized to disrupt the botnet’s infrastructure — cutting off communication channels critical for its operators. The domain seizures render QTFY “inoperable” for the communication portion of its scheme.
This latest move follows a growing pattern of U.S. legal actions targeting foreign cyber infrastructure used for intelligence operations. While domain seizures are common, tying them to such high-profile intrusions – including NASA and the Senate – is relatively rare in public filings.
Why this matters: QTFY represents a hybrid model of cyber attack infrastructure — combining criminal botnet techniques with state-directed espionage tools. By dismantling its domain backbone, U.S. authorities deal significant disruption to China’s low-risk proxy operations in cyberspace. Going forward, watch for retaliatory moves, changes in U.S. cyber policy, and how this influences global norms around attributing and responding to state-linked cyber threats.