US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
美国查封用于攻击美国国家航空航天局(NASA)、司法部及参议院的中国僵尸网络域名
The FBI has seized a series of domains that were used by a large-scale botnet to coordinate and launch China-backed cyberattacks against American targets. 美国联邦调查局(FBI)查封了一系列域名,这些域名曾被一个大规模僵尸网络用于协调和发起针对美国目标的、由中国支持的网络攻击。
According to the Justice Department’s statement on Wednesday, the seizures of the botnet’s domains deny the operators access to the platforms. The botnet was allegedly used by the Chinese government to break into computers across the United States, including systems at hospitals, defense contractors, and several federal government departments. 根据司法部周三发表的声明,查封这些僵尸网络域名切断了运营者对相关平台的访问权限。据称,该僵尸网络被中国政府用于入侵美国各地的计算机,包括医院、国防承包商以及多个联邦政府部门的系统。
Prosecutors said the China state-sponsored group, known as QTFY, was run by a Chinese company called Nanjing Xinjiuwei Network Tech, which created and operated the botnet of thousands of thousands of compromised internet-connected devices. The botnet aimed to serve as obfuscation networks, which hide the malicious traffic of hackers to make their activity more difficult to detect. 检察官表示,这个名为“QTFY”的中国国家支持组织由一家名为南京信久威网络科技有限公司(Nanjing Xinjiuwei Network Tech)的中国公司运营,该公司创建并操控了这个由数千台被入侵的联网设备组成的僵尸网络。该僵尸网络旨在充当混淆网络,隐藏黑客的恶意流量,从而使他们的活动更难被察觉。
Per the Justice Department, QTFY offers computer hacking services to its customers, who include Chinese government hackers working for the Ministry of State Security, and allows them to use the botnet. The hacks date back to 2018 and affected NASA, the Federal Reserve, and the Departments of Energy, Justice, and Health and Human Services. 据司法部称,QTFY 向其客户提供计算机黑客服务,客户包括为中国国家安全部工作的政府黑客,并允许他们使用该僵尸网络。这些黑客攻击最早可追溯至 2018 年,受影响机构包括 NASA、美联储,以及能源部、司法部和卫生与公众服务部。
The U.S. Senate was compromised as recently as 2026, according to the government’s affidavit seeking a court order to seize the botnet’s domains filed earlier this week. The Justice Department said that the domain seizures made the botnet and its command and control servers “inoperable,” as the domains were hardcoded into the botnet’s code and were critical for the botnet’s communication and essential operations. 根据政府本周早些时候提交的申请查封僵尸网络域名的法院令宣誓书,美国参议院在 2026 年近期仍遭到入侵。司法部表示,此次域名查封使该僵尸网络及其指挥与控制服务器“无法运作”,因为这些域名被硬编码在僵尸网络的代码中,对于其通信和基本操作至关重要。
Network giant Lumen said in a blog post that it had observed the hackers profiling and targeting government agencies, the defense and aerospace sectors, and others for the past year, and shared threat intelligence with the FBI. 网络巨头 Lumen 在一篇博文中表示,过去一年中,他们观察到黑客对政府机构、国防和航空航天部门等目标进行了画像和攻击,并已与 FBI 分享了相关威胁情报。