FBI dismantles China-linked botnet infrastructure targeting U.S. agencies
The FBI has taken control of domains tied to a botnet operated by a Chinese firm, which provided cover for state-sponsored hacking campaigns. The infrastructure was used to breach multiple U.S. government agencies, including NASA and the Federal Reserve, since 2018. The seizure effectively disabled the botnet's command-and-control capabilities, according to the Justice Department.
The seized infrastructure relied on thousands of compromised internet-connected devices to form a relay network, masking the origin of malicious traffic from Chinese state hackers. The Justice Department's court filing noted the U.S. Senate was breached as recently as 2026, extending the campaign's timeline well beyond its 2018 origins.
Lumen Technologies, the network provider, had observed the threat actors profiling government agencies and defense contractors for roughly a year before the takedown, sharing its findings with federal investigators. Because the domains were embedded directly into the botnet's code, the seizure severed command-and-control communications entirely, rendering the operation inoperable.
The takedown could have ripple effects beyond the immediate disruption, as other threat actors may study the technique and adapt. Government agencies and critical infrastructure operators may need to reassess their exposure, given that breaches persisted for years undetected. The incident may also influence how private sector firms share threat intelligence with law enforcement, potentially accelerating similar collaborative efforts against state-sponsored cyber operations.