The FBI and U.S. Justice Department have seized domains tied to an alleged China-backed botnet used in intrusions against U.S. government systems and other targets, according to reports from Tom’s Hardware and TechCrunch based on Justice Department statements and court filings. The alleged group is known as QTFY. Prosecutors say it was run by a Chinese company identified as Nanjing Xinjiuwei Network Technology or Nanjing Xinjiuwei Network Tech, and that it provided hacking services to customers that included hackers working for China’s Ministry of State Security, according to both outlets. The botnet’s purpose, as described by the Justice Department in the reports, was not only to compromise systems but to hide where malicious traffic was coming from. Tom’s Hardware reports that the government named two pieces of malware, QScan and QTRouter: QScan allegedly scans for and infects internet-connected devices, which are then added to the QTRouter network. TechCrunch similarly reports that QTFY operated thousands of compromised internet-connected devices as obfuscation networks. The reported targets were broad. Both outlets say affected entities included NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, and the U.S. Senate. Tom’s Hardware also reports that the National Institutes of Health experienced computer intrusion activity, while TechCrunch says systems at hospitals and defense contractors were also among the targets. The activity allegedly goes back years. TechCrunch, citing the government’s affidavit seeking a court order for the domain seizures, reports that the hacks date to 2018 and says the U.S. Senate was compromised in 2026. Tom’s Hardware reports that an FBI investigation began as early as 2019 after a NASA intrusion linked to CVE-2019-11510, a vulnerability that was later patched. Tom’s Hardware names the seized domains as qtproxy.xyz, qt-proxy.org, and qt-team.com, and reports that the FBI said the group obtained them between 2022 and 2024 through Namecheap and paid using PayPal. TechCrunch reports that the Justice Department said taking the domains denied the operators access to key botnet infrastructure because the domains were hardcoded into the botnet’s code and were essential for command-and-control operations. TechCrunch also reports that network company Lumen said it had observed the hackers profiling and targeting government agencies, defense and aerospace organizations, and other sectors over the past year, and that it shared threat intelligence with the FBI. The reports do not say, in the provided material, whether charges were filed against specific individuals. Who benefits: U.S. investigators and targeted organizations benefit if the seized domains materially disrupt the botnet’s command-and-control infrastructure, as the Justice Department claims. Security teams also get a clearer view of the alleged infrastructure and targeting pattern described in the filings. Who's exposed: Government agencies, hospitals, defense contractors, aerospace organizations, and operators of internet-connected devices may remain exposed to this class of activity. The reports describe thousands of compromised internet-connected or IoT devices worldwide.