Interestana
Home/News/US Seizes Chinese Botnet Domains Used in Government Hacks
TechCrunch3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

US Seizes Chinese Botnet Domains Used in Government Hacks

The Federal Bureau of Investigation (FBI) has seized multiple internet domains that were instrumental in operating a sophisticated botnet controlled by Chinese state-sponsored hackers. This botnet was employed to conduct extensive cyber intrusions targeting various sensitive United States government agencies. The operation, announced by the U.S. Department of Justice on May 23, 2024, marks a significant effort to disrupt and dismantle cyber threats originating from the People's Republic of China. The seized domains were part of a network that facilitated unauthorized access to computer systems belonging to agencies such as the National Aeronautics and Space Administration (NASA) and the Department of Justice itself. Furthermore, the investigation revealed that the botnet's infrastructure was also used to compromise systems within the United States Senate. The FBI's investigation, codenamed "Operation Lunar Net," identified the botnet as "Andr/Coin-Dropper" and "Andr/GenericKD-S," indicating its multi-purpose malicious capabilities. This botnet was designed to compromise internet-connected devices, turning them into remotely controlled "bots" that could be marshaled for various cybercriminal activities. The specific nature of the breaches into NASA and the Senate was not fully detailed, but the Justice Department stated that the botnet enabled hackers to gain unauthorized access and potentially exfiltrate sensitive data. The operation involved coordinated action with international law enforcement partners, underscoring the global nature of cyber threats. The U.S. government has consistently warned about the persistent threat posed by Chinese cyber operations, which often involve espionage, intellectual property theft, and disruption of critical infrastructure. The seizure of these domains is intended to degrade the operational capacity of these Chinese hacking groups, making it more difficult for them to launch future attacks. The Department of Justice emphasized that this action is part of an ongoing commitment to hold malicious cyber actors accountable and protect national security interests. The investigation into the full extent of the botnet's activities and the identities of the individuals behind it remains active. The U.S. government has previously attributed numerous cyberattacks to China, citing state-sponsored groups engaging in activities ranging from economic espionage to the targeting of political and military entities. This latest action highlights the persistent and evolving threat landscape in cyberspace and the proactive measures being taken by U.S. authorities to counter it.

Original source — read the full reporting at the publisher:

Read on TechCrunch

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next