FBI Seizes Chinese Hacking Domains Targeting NASA, Federal Agencies

3 min readSources: Wired

DOJ and FBI seized domains of Chinese hacking tools targeting US government agencies.

Why it matters: Nation-state cyberattacks threaten critical government infrastructure, making cybersecurity and compliance essential for legal teams. Understanding these tactics helps prepare defense and risk mitigation strategies.

  • On August 26, 2026, DOJ and FBI seized domains tied to Chinese hacking platforms QScan and QTRouter.
  • QScan and QTRouter controlled a botnet utilizing thousands of compromised IoT devices to mask attacks.
  • Targets included NASA, the Federal Reserve, the U.S. Senate, and multiple federal departments.
  • NSA issued an advisory detailing the QTFY group's hacking tactics, active since at least 2018.

On August 26, 2026, the U.S. Department of Justice and FBI announced they seized command and control domains of two hacking platforms, QScan and QTRouter. These tools, operated by the Chinese state-sponsored hacking group QTFY via Nanjing Xinjiuwei Network Technology Company, targeted key U.S. government infrastructure.

The FBI actively disrupted this botnet by seizing domains hard-coded into the malware, shutting down QScan and QTRouter’s ability to control infected devices. The botnet worked by infecting thousands of Internet-of-Things (IoT) devices, using them to route malicious traffic and obscure attack origins.

Targets of these cyberattacks included NASA, the Federal Reserve, the U.S. Senate, and several federal departments. The National Security Agency (NSA) issued an advisory outlining QTFY’s tactics and activities dating back at least to 2018.

Attorney General Todd Blanche stated, "We will continue to use every tool at our disposal to protect U.S. infrastructure from state-sponsored cyberattacks." Assistant Attorney General John A. Eisenberg noted that court-authorized domain seizures deny hackers access to critical tools needed for attacks.

Cybersecurity experts outside the government emphasize that disrupting control domains effectively neutralizes botnets temporarily but stress the need for continuous vigilance. "These operations hamper attackers but require ongoing coordination between government and private sectors to strengthen defenses," said independent analyst Karen Liu of CyberSecure Analytics.

This seizure reflects broader U.S. efforts to counter persistent cyber threats from foreign state actors, complementing previous actions against Chinese hacking groups deploying surveillance malware within the country.

By the numbers:

  • August 26, 2026 — DOJ and FBI seized QScan and QTRouter domains
  • Thousands — IoT devices infected and exploited by QScan and QTRouter botnet
  • 2018 — Earliest recorded activity of QTFY hacking group per NSA advisory

Yes, but: While domain seizures disrupt botnet operations, experts warn that threat actors adapt quickly, requiring sustained cybersecurity efforts beyond single takedowns.

What's next: Legal and cybersecurity communities will watch for further DOJ/FBI actions against QTFY and related groups as investigations continue.