AI News AI资讯 10h ago Updated 1h ago 更新于 1小时前 44

US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate 美国查封中国僵尸网络域名,该网络曾用于入侵NASA、司法部和参议院

The FBI seized domains controlling a large-scale botnet used by China-backed hackers (group QTFY, operated by Nanjing Xinjiuwei Network Tech) to compromise U.S. government and critical infrastructure systems The botnet served as an obfuscation network, masking malicious traffic to evade detection while coordinating attacks on hospitals, defense contractors, NASA, the Federal Reserve, and multiple federal departments Domain seizures rendered the botnet and its command-and-control servers inoperab FBI查封了由中国支持的僵尸网络QTFY的域名,该僵尸网络用于协调针对美国关键基础设施的网络攻击 该僵尸网络由南京新九微网络科技有限公司运营,作为混淆网络隐藏黑客恶意流量,为包括中国国家安全部黑客在内的客户提供服务 攻击目标包括NASA、美联储、能源部、司法部、卫生与公众服务部及参议院等美国政府机构,攻击活动从2018年持续至2026年 域名被硬编码到僵尸网络代码中,查封后使僵尸网络指挥控制服务器无法运作 Lumen公司通过威胁情报共享协助FBI成功打击此次网络攻击行动

72
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • The FBI seized domains controlling a large-scale botnet used by China-backed hackers (group QTFY, operated by Nanjing Xinjiuwei Network Tech) to compromise U.S. government and critical infrastructure systems
  • The botnet served as an obfuscation network, masking malicious traffic to evade detection while coordinating attacks on hospitals, defense contractors, NASA, the Federal Reserve, and multiple federal departments
  • Domain seizures rendered the botnet and its command-and-control servers inoperable, as the domains were hardcoded into the botnet's infrastructure
  • The campaign spanned from 2018 to at least 2026, with the U.S. Senate compromised as recently as 2026
  • Lumen provided critical threat intelligence to the FBI, observing the hackers profiling government agencies and defense/aerospace sectors over the past year

Why It Matters

This case illustrates the growing intersection of state-sponsored cyber warfare and commercial botnet-as-a-service models, where private companies operate hacking infrastructure for foreign governments. For AI and cybersecurity practitioners, it underscores the importance of monitoring command-and-control domain patterns and the value of private-sector threat intelligence sharing in disrupting nation-state operations.

Technical Details

  • Botnet Architecture: The botnet consisted of thousands of compromised internet-connected devices, with command-and-control servers hardcoded with specific domains that enabled communication and essential operations between infected nodes and operators
  • Obfuscation Strategy: The botnet functioned as an obfuscation network, routing malicious traffic through compromised devices to hide the origin and nature of hacking activities, making detection significantly more difficult
  • Target Profile: Victims included NASA, the Federal Reserve, Departments of Energy, Justice, and Health and Human Services, defense contractors, hospitals, and the U.S. Senate — indicating a focus on high-value government and critical infrastructure targets
  • Service Model: QTFY operated on a botnet-as-a-service basis, offering hacking infrastructure to customers including Ministry of State Security operatives, who could leverage the compromised device pool for their own operations
  • Disruption Method: The FBI's domain seizure directly neutralized the botnet by removing hardcoded C2 domains, demonstrating how infrastructure dependency can be exploited for large-scale takedowns

Industry Insight

  • The botnet-as-a-service model blurs the line between criminal enterprises and state actors, suggesting that governments may increasingly outsource cyber operations to commercial entities for plausible deniability — a trend organizations should monitor in threat intelligence frameworks
  • Hardcoded C2 domains represent a critical single point of failure; defenders should prioritize detecting and blocking known botnet infrastructure patterns and implement DNS-level monitoring for anomalous command-and-control communication
  • The 2026 Senate compromise highlights that nation-state intrusions can persist undetected for years; organizations should assume breach and adopt zero-trust architectures with continuous monitoring rather than relying on perimeter defenses alone

TL;DR

  • FBI查封了由中国支持的僵尸网络QTFY的域名,该僵尸网络用于协调针对美国关键基础设施的网络攻击
  • 该僵尸网络由南京新九微网络科技有限公司运营,作为混淆网络隐藏黑客恶意流量,为包括中国国家安全部黑客在内的客户提供服务
  • 攻击目标包括NASA、美联储、能源部、司法部、卫生与公众服务部及参议院等美国政府机构,攻击活动从2018年持续至2026年
  • 域名被硬编码到僵尸网络代码中,查封后使僵尸网络指挥控制服务器无法运作
  • Lumen公司通过威胁情报共享协助FBI成功打击此次网络攻击行动

为什么值得看

此次行动展示了国家级网络攻击的长期潜伏特征和僵尸网络作为攻击基础设施的重要性,为网络安全从业者提供了关于国家支持黑客活动模式的重要参考。域名硬编码的技术细节揭示了执法部门如何通过精准打击通信基础设施来瘫痪僵尸网络,对防御策略具有指导意义。

技术解析

  • QTFY僵尸网络由南京新九微网络科技有限公司运营,包含数千台被入侵的物联网设备,作为混淆网络隐藏黑客恶意流量,为包括中国国家安全部黑客在内的客户提供计算机黑客服务
  • 攻击目标涵盖NASA、美联储、能源部、司法部、卫生与公众服务部及参议院等美国政府机构,攻击活动从2018年持续至2026年
  • 域名被硬编码到僵尸网络代码中,作为指挥控制服务器的关键通信基础设施,查封后使整个僵尸网络无法运作
  • Lumen公司通过威胁情报共享协助FBI识别和定位僵尸网络的域名基础设施

行业启示

  • 国家支持的网络攻击往往通过商业公司作为掩护,采用长期潜伏策略,攻击者可能潜伏多年后才被发现,企业需建立持续监控机制
  • 域名硬编码是僵尸网络的常见技术特征,执法部门可通过查封关键域名有效瘫痪整个僵尸网络基础设施,这一模式可复制到其他案例
  • 网络安全公司的情报共享对打击国家级网络攻击至关重要,Lumen与FBI的合作模式值得推广,行业应加强公私合作机制

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Policy 政策 Regulation 监管