On August 26th, the United States Department of Justice indicated that the FBI had seized a number of domain names to control zombie networks. According to the United States, the network was used by Chinese government background hackers to coordinate and launch cyberattacks against United States targets, including federal agencies, hospitals and defence contractors.

Domain name blocked and network shut down.

According to the Ministry of Justice, the sealed domain name was originally used for command and control communications of the zombie network. As these domain names are included in the malicious program code, the relevant network and its control server cannot continue to function after law enforcement operations have been completed.

Affected institutions date back to 2018

According to the United States Department of Justice, this invasion dates as far back as 2018 and affects a number of United States Government departments and agencies, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice and the Department of Health and Human Services.

The Court's affidavit submitted earlier this week by the United States Government also mentioned that the United States Senate had also been invaded in 2026. This means that the attacks did not stop at an early stage, but continued for many years.

QTFY provides hacking services

According to the Ministry of Justice, QTFY provided computer intrusion services to its customers and allowed them to use the zombie network described above. According to the United States, these clients included hackers working for the Chinese Ministry of National Security.

From the United States perspective, the network is not only a single attack tool, but more like an infrastructure that can be used by different operators. The focus of the seizure was to cut off the key nodes of its communications and movement control attacks.

Lumen gave the FBI information.

In a blog, Lumen, a network service company, indicated that the past year had seen hackers carrying out graphic and targeted activities in government agencies, defence and aerospace, and had shared threat information with the FBI.

This indicates that the enforcement operation was not a stand-alone move but was based on long-term company-side monitoring and intelligence-sharing. The United States Department of Justice currently does not disclose further details of the victimization system in its statement.