The FBI has seized domain infrastructure behind a botnet that Chinese state-backed hackers used to breach NASA, the Justice Department, and the U.S. Senate.
The FBI took control of the domains anchoring the botnet's infrastructure, according to the bureau. That network gave hackers a route into at least three federal entities: NASA, the Justice Department, and the Senate. Officials have attributed the intrusions to Chinese state-backed actors, though how each breach happened and what was accessed have not been detailed publicly. The seizure disables the botnet's current infrastructure; it does not undo the initial breaches.
Botnets like this one are the connective tissue of state-sponsored hacking: unremarkable networks of compromised devices or servers that let intelligence services route traffic anonymously into sensitive targets. Hitting NASA, the Justice Department, and the Senate in one campaign points to broad, opportunistic reconnaissance rather than a narrowly scoped operation. That the FBI could map and seize this infrastructure suggests the bureau had been tracking it for some time before acting.
Seizing domains makes a tidy headline, but it rarely kills the operation. Well-funded state actors typically stand up new infrastructure within days, treating a takedown like this as a cost of doing business, not a stop sign.