Observed Signal · Aug 26, 2026 · Legal Action · Source: techcrunch · Impact: 2/5 · Sentiment: Neutral

US Seizes Domains of China-Linked Botnet

Executive Signal Summary

The U.S. Department of Justice and FBI seized a set of domains used to operate a large China-linked botnet that prosecutors say was run by Nanjing Xinjiuwei Network Tech and supplied to a China state-sponsored group known as QTFY. The botnet — composed of thousands of compromised devices and using hardcoded domains for command-and-control — has been tied to intrusions dating back to 2018 affecting NASA, the Federal Reserve, hospitals, defense contractors and multiple federal departments. The government affidavit says the U.S. Senate was compromised as recently as 2026. The DOJ said seizing the domains rendered the botnet inoperable. Network operator Lumen reported observing the attackers and shared threat intelligence with the FBI.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

U.S. law enforcement action disrupted a large state-linked botnet that targeted major institutions; important for cybersecurity and threat intelligence but has limited direct, immediate impact on the AdTech industry.

SIGNAL RADAR

Track TechCrunch Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • The U.S. Department of Justice and FBI seized domains used to operate a large China-linked botnet.
  • Prosecutors allege the state-sponsored group QTFY was run by Chinese company Nanjing Xinjiuwei Network Tech.
  • The botnet, active since at least 2018, targeted NASA, the Federal Reserve, the Departments of Energy, Justice, Health and Human Services, hospitals, defense contractors, and the U.S. Senate (compromised as recently as 2026).
  • The DOJ said the seized domains were hardcoded into the botnet and that the seizures made its command-and-control infrastructure inoperable.
  • Lumen observed the attackers' activity, shared threat intelligence with the FBI, and documented profiling of government and defense targets.

Connected Companies & Entities

1 Entity mapped
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Aug 26, 2026
Original Coverage Title: “US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Advertising Quality (Fraud & Bot Mitigation)Mar 12, 2026

Global Crackdown Dismantles Massive Router Botnet Operation

A global law enforcement coalition dismantled SocksEscort, a paid proxy service built on a botnet of hacked home and small-business routers. The U.S. Department of Justice said SocksEscort’s infrastructure was used to commit widespread crimes — including account takeovers, fraudulent unemployment claims, ransomware facilitation, DDoS attacks, and distribution of CSAM — that cost Americans millions. Europol reported the botnet had compromised more than 369,000 routers and IoT devices across 163 countries and that infected devices were disconnected from the service. Cybersecurity firm Black Lotus Labs, which tracked the operation and assisted law enforcement, said the botnet was powered by AVRecon malware and had been composed of roughly 280,000 routers since January. The SocksEscort site was seized as part of the operation.

Read assessment
CybersecurityMar 5, 2026

FBI Networks Breached: Hackers Target Surveillance Systems

TechCrunch reports that hackers breached FBI networks, reportedly affecting a system used to manage wiretaps and foreign intelligence surveillance warrants, according to CNN. The FBI told TechCrunch it identified and addressed suspicious activity on its networks and used technical capabilities to respond but declined to provide details. The article places the incident in the context of recent major intrusions into U.S. government and corporate systems, noting prior breaches of the U.S. Treasury, the National Nuclear Security Administration, and the U.S. Courts’ filing system. The piece also cites the FBI saying the Chinese government-linked hacking group Salt Typhoon has compromised at least 200 U.S. companies, with confirmed victims including AT&T, Verizon, Lumen, Charter Communications and Windstream.

Read assessment
Advertising Quality (Fraud & Bot Mitigation)Mar 20, 2026

Authorities Take Down Two Major DDoS Botnets

German and North American law-enforcement agencies disrupted the infrastructure of two of the world’s largest botnets — Aisuru and Kimwolf — which were used to launch large-scale distributed-denial-of-service (DDoS) attacks. The Bundeskriminalamt (BKA) and Nordrhein‑Westfalen’s ZAC, together with Canadian and U.S. authorities, disabled the globally distributed technical infrastructure but did not make arrests. Authorities identified two suspected administrators and seized extensive evidence during searches in Germany and Canada, including data drives and five-figure sums in cryptocurrency. Aisuru is linked to massive IoT-based attacks (including an attributed 31.4 Tbps DDoS mitigated by Cloudflare); Kimwolf is closely related and focused more on Android and consumer devices such as TV boxes. The primary targets of past DDoS incidents have included public services and apps, for example Germany’s Deutsche Bahn and its DB Navigator app.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.