FBI disrupts proxy network enabling Chinese espionage operations

FBI disrupts proxy network enabling Chinese espionage operations

The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.

Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking the infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure.

According to the researchers, the provider offers a reusable service consisting of four distinct operational elements:

image
  • QScan: a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating-system fingerprints, and configuration data
  • Fast Labyrinth: an encrypted relay network that conceals communications to and from victim organizations
  • QTRouter: provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system
  • QTProxy: a management tool that lets users select relays and configure custom routes through Fast Labyrinth
Overview of the Quartermaster infrastructure
Overview of the quartermaster infrastructureSource: Lumen

The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors.

“Lumen Technologies would like to commend the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure,” reads the report.

“During our investigation, Black Lotus Labs shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact our nation’s strategic assets.”

The researchers also note that they have disrupted the infrastructure by null-routing the traffic to known infrastructure points used by the quartermaster operators.

Building an evasive ORB network

Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators.

ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used for relaying malicious traffic and to obscure its true source.

Chinese threat actors have increasingly leveraged ORBs in cyber operations since 2024 and intensified this activity earlier this year.

In the case of the “quartermaster,” instead of building a conventional ORB network from thousands of compromised devices, the platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws.

Fastlink nodes
Fastlink nodesSource: Lumen

These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure.

The researchers highlight the overlap between QScan targets and organizations later contacted through Fast Labyrinth as the strongest piece of evidence connecting reconnaissance to follow-up operations.

QScan information pipeline
QScan information pipelineSource: Lumen

Lumen assesses that the observed bidirectional connections from the proxy network likely represent attempted exploitation, lateral movement, persistent access, or data collection.

Although disrupting this provider is significant, Lumen warns that static blocking alone is unlikely to be effective in this case because the quartermaster’s traffic passes through dynamically rotating commercial proxy services.

Defenders are recommended to follow CISA and NCSC guidance for mitigating China-nexus threats and to keep routers, firewalls, and IoT devices up to date and securely configured.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report
source: BleepingComputer