Washington seizes the domains behind a Chinese hacking platform that reached NASA, the Federal Reserve and the Senate

World News

Washington seizes the domains behind a Chinese hacking platform that reached NASA, the Federal Reserve and the Senate

By Staff Writer  |  27 August 2026

The concrete frontage of the Federal Bureau of Investigation headquarters in Washington

Court papers unsealed in southern California name a company in Nanjing as the operator of two tools that hid the origin of intrusions running back to 2018. Seizing the domains made both inoperable.

American prosecutors and the federal bureau took control of the domain names behind two linked hacking platforms on Wednesday, in an operation authorised by a court in the Southern District of California. The department says the platforms were built and run by a Chinese state sponsored group and used against critical infrastructure and other sensitive networks in the United States.

The list of organisations named as victims in the court papers is the part practitioners will read twice: the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health and the United States Senate.

State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted

Todd Blanche, Attorney General of the United States

How the two tools worked together

The department describes a pair of programs that operate as a chain. The first scans the open internet and infects connected devices of the kind that sit in buildings and plant rooms rather than in data centres: cameras, controllers, routers and the rest of the internet of things. Machines taken that way are enrolled into the second tool, which the department calls an obfuscation network and which also draws on commercial proxy services and rented virtual servers.

The point of the second tool is not to break in. It is to make the traffic that breaks in appear to come from somewhere other than China, and in some cases from a machine on the target's own doorstep. A defender looking at the logs sees a neighbour, not a foreign service.

These tools were used by PRC cyber actors to hide the origin of their attacks

Kash Patel, Director of the Federal Bureau of Investigation

The seizures worked because the domain names were written into the software itself and used for the tasks the two tools cannot do without, communication between the parts and authentication of the operator. Taking the names out from under the code stopped both.

These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure

John A. Eisenberg, Assistant Attorney General for National Security

What the papers allege about the customers

According to the court documents, the group sold hacking services to paying customers, and those customers included China's Ministry of State Security and the People's Liberation Army. The group is said to have been employed by a network technology company based in Nanjing. Those are allegations in unsealed filings and no court has determined them.

Alongside the seizures, the bureau and the national security agency published an advisory setting out indicators of compromise attributed to the group and dating back to at least 2018. Three earlier operations of the same shape are cited in the department's release: surveillance software removed from more than four thousand American computers in 2025, a botnet of infected connected devices disabled in 2024, and a further botnet disrupted in 2023.

The device class at the centre of this is the one the construction industry installs and then forgets. Building management controllers, access control panels, plant room gateways and site cameras are commissioned once, rarely patched and often left on the network the client uses for everything else. A contractor that hands over an unhardened building system is handing over a node, and the handover documents almost never say who owns the patching after practical completion.

The domains are gone and the two tools are inoperable. The compromised devices they were assembled from are still sitting where they were installed.