US Seizes Domains from Chinese Hacking Group Targeting Critical Infrastructure

US Seizes Domains from Chinese Hacking Group Targeting Critical Infrastructure

First seen 26 Aug 2026, 20:38 UTC Ua.NewsZamin.UzUpiUk.News.Yahoo 77.9

Article Content

Browse articles
ThreatCluster

The FBI and DOJ have seized domains linked to a Chinese state-backed hacking group named QTFY, which has targeted US government agencies and critical infrastructure since 2018. The group, associated with Nanjing Xinjiuwei Network Technology Company, used a botnet to conduct cyberattacks against entities such as NASA, the Federal Reserve, and various federal departments. The seized domains were integral to the botnet's operations, effectively disabling its command-and-control capabilities. The attacks have raised significant concerns regarding the security of US critical infrastructure, with reports indicating that the group has been active for years, employing sophisticated methods to mask their activities. The DOJ's actions aim to disrupt ongoing cyber-espionage efforts attributed to the Chinese government. The FBI has also released advisories to help organizations defend against potential future attacks.

Key Points: • The QTFY group has targeted US agencies since 2018, affecting critical infrastructure. • Domains seized were essential for the botnet's command-and-control operations. • The DOJ's actions aim to disrupt ongoing cyber-espionage linked to the Chinese government.

Timeline

2018-01-01
QTFY group begins operations
The Chinese state-linked group QTFY starts targeting US critical infrastructure and government agencies.
Uk.News.Yahoo
2024-09-01
QTFY conducts intrusions
The group reportedly conducts computer intrusions at three Energy Department laboratories and NIH.
Uk.News.Yahoo
2026-08-26
US seizes QTFY domains
The DOJ and FBI announce the seizure of domains used by QTFY, disrupting their operations.
Upi