Silhouette of a soldier using a laptop in front of a red flag with yellow stars.

Digital Takedown: Federal Agents Seize Web Domains Powering Chinese Cyber Espionage Network

Federal law enforcement seized web domains that powered a massive botnet responsible for state-sponsored attacks against critical American institutions. The Department of Justice announced Wednesday that federal authorities took over key infrastructure to block operators from accessing the network and launching fresh exploits.

State-backed hackers linked to the Chinese government used the botnet to infiltrate thousands of secure systems across the country. Target list entries included military contractors, healthcare networks, regional hospitals, and high-level government agencies.

Federal prosecutors named the Chinese threat group as QTFY. A commercial entity called Nanjing Xinjiuwei Network Tech created, updated, and managed the botnet for state operations. The company infected thousands of smart devices, router setups, and internet-connected hardware to form a protective proxy network. This setup routed malicious traffic through everyday household gear, disguising origin locations and hiding intruder activity from network defenders.

Unsealed court documents show that QTFY sells specialized hacking access to external buyers. Primary customers include Chinese intelligence operators working for the Ministry of State Security. These state agents used the infected network to run cover for sensitive intelligence operations, stealing files and gathering data without raising alarms.

Intrusions tied to this network stretch back to 2018. Over the years, hackers compromised networks at NASA, the Federal Reserve, the Department of Energy, the Department of Justice, and the Department of Health and Human Services. The group also breached systems inside the United States Senate as recently as 2026.

Taking control of these web domains broke command channels entirely. Because operators hardcoded specific domain names into the core software, seizing the web addresses cut communication lines between the control servers and infected devices, leaving the botnet broken and unusable.

Network security firm Lumen tracked the hacking group over the past year. Analysts noticed operators profiling targets across aerospace, defense, and civil government sectors. Lumen shared its threat logs directly with federal investigators to help pinpoint key servers and build the legal case for seizure.

Securing vulnerable connected devices remains a continuous challenge. Hackers continuously search for outdated routers, smart home gear, and unpatched hardware to expand their networks. Unsafe consumer devices quickly turn into launchpads for state-sponsored espionage when owners leave factory passwords unchanged.

Seizing web domains delivers a heavy blow to hostile cyber networks, but keeping systems safe requires constant vigilance. Organizations must update software regularly, block unauthorized proxy traffic, and monitor network logs to prevent hidden intrusions from compromising critical assets.