FBI Seizes Chinese Botnet Domains Behind Hacks of NASA, DOJ and US Senate

FBI Seizes Chinese Botnet Domains Behind Hacks of NASA, DOJ and US Senate

TL;DR

  • The FBI has seized multiple domains linked to a massive Chinese state-sponsored botnet that infiltrated networks at NASA, the Department of Justice, and the U.S. Senate, exfiltrating sensitive data for years.
  • The botnet, operated by hackers tied to the Chinese government, hijacked hundreds of thousands of compromised routers, IoT devices, and servers worldwide to create a stealthy proxy network for espionage.
  • The court-authorized takedown marks a major escalation in the U.S. offensive against Chinese cyber operations, but officials warn the underlying threat from groups like Flax Typhoon and Volt Typhoon remains active.

A Stealth Network Hiding in Plain Sight

For years, a sprawling network of compromised devices operated quietly in the background of the internet, masking its true purpose. According to federal officials, it wasn't a typical cybercriminal enterprise chasing financial gain. It was a state-sponsored espionage tool built to give Chinese government hackers covert, persistent access to some of America's most sensitive government networks.

This week, the Federal Bureau of Investigation moved to dismantle it. In a coordinated operation with the Department of Justice and private sector partners, the FBI announced the court-authorized seizure of the domains and internet infrastructure that served as the command-and-control backbone for the botnet.

The announcement confirms what intelligence agencies have warned about for months: Chinese state-backed actors have deeply embedded themselves in U.S. critical infrastructure and government systems, using highly sophisticated methods to avoid detection.

How the Botnet Worked: A Million-Device Ghost Network

Unlike a traditional hack that directly attacks a target, this botnet relied on indirection and scale. Investigators say the operators, linked to a Chinese company acting as a front for state intelligence, infected over 260,000 internet-connected devices globally, including small-office/home-office (SOHO) routers, network-attached storage devices, IP cameras, and other IoT hardware.

Most device owners had no idea their hardware was compromised. Once infected with custom malware, the devices were linked together into what the FBI described as a "botnet proxy service."

This network served two critical functions for the hackers. First, it provided a massive, anonymized laundering system for their traffic. When hackers from China attacked NASA or the Senate, their activity appeared to come from a compromised home router in Ohio or California, not from overseas. Second, it created a resilient and distributed command-and-control system that was extremely difficult to trace and take down.

Federal court documents allege the botnet was operated by Integrity Technology Group, a Beijing-based company previously identified by the FBI as a cover for hackers working for China's Ministry of State Security and linked to the group tracked as Flax Typhoon, also known as Raptor Train.

The Scale of the Breach: NASA, DOJ, and the Senate Compromised

The seizure filings reveal the staggering scope of the espionage campaign. By routing their attacks through the botnet, the hackers were able to conduct highly targeted intrusions and steal sensitive information while evading advanced defense systems.

Officials confirmed the botnet was used to breach and exfiltrate data from several high-value U.S. government and institutional targets:

At NASA, the hackers accessed internal networks and exfiltrated data related to sensitive research and administrative systems. At the Department of Justice, the intrusion targeted systems containing law enforcement data. The breach of the U.S. Senate network is considered particularly alarming, with investigators assessing that the actors sought internal communications and data that could provide intelligence on U.S. legislative processes and policy deliberations.

Beyond the federal government, the same infrastructure was used to target universities, defense contractors, media organizations, and critical infrastructure companies across the U.S., Taiwan, and Europe. The FBI noted that the botnet was active since at least 2020, giving the actors years of persistent access.

Operation Takedown: How the FBI Pulled the Plug

The takedown was not a simple server shutdown. Because the botnet was so decentralized, the FBI had to pursue a legal and technical strategy to sever the attackers' control.

After months of investigation with partners including the National Security Agency, the Cybersecurity and Infrastructure Security Agency (CISA), and cybersecurity firms like Lumen's Black Lotus Labs, the FBI obtained a court order to seize the domains that the infected devices used to communicate with the operators.

By taking control of those domains and redirecting them to FBI-controlled sinkhole servers, agents were able to cut the link between the hackers and their army of zombie devices. The operation also included issuing commands to the infected devices to remove the malware where possible, though officials are urging anyone with SOHO routers or IoT devices to reboot their hardware and apply the latest security patches and firmware updates.

Attorney General and FBI leadership described the action as a "disrupt and degrade" mission — not just to stop the current intrusions, but to burn the infrastructure and force the adversary to rebuild from scratch, costing them time and money.

What This Signals for America's Cyber Defense

The seizure is the latest in a series of aggressive U.S. actions against Chinese cyber operations, following last year's takedown of the Volt Typhoon botnet that had positioned itself inside U.S. critical infrastructure networks like water and energy systems.

Together, these operations signal a clear shift in U.S. strategy from purely defensive postures to proactive, offensive disruption. Instead of just patching vulnerabilities after a breach, U.S. Cyber Command and the FBI are now hunting and dismantling adversary infrastructure before it can be used for a larger attack.

However, officials were quick to caution that the takedown is not a final victory. While the command-and-control domains have been seized, the threat actors themselves remain at large in China, outside U.S. jurisdiction, and are already expected to attempt to rebuild.

CISA has released new guidance urging government agencies and private organizations to adopt stronger network segmentation, replace end-of-life routers, and disable remote management features that the botnet exploited.

The message from federal agencies is clear: the botnet may be down, but the campaign is far from over. This takedown has exposed how deeply state-sponsored hackers have woven themselves into the fabric of everyday internet devices, and defending against the next botnet will require a collective effort from government, industry, and consumers alike.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
FBI Seizes Chinese Botnet Domains Behind Hacks of NASA, DOJ and US Senate FBI Seizes Chinese Botnet Domains Behind Hacks of NASA, DOJ and US Senate Reviewed by Randeotten on 8/26/2026 11:46:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.