FBI disrupts proxy network enabling Chinese espionage operations
This digest was compiled by AI from multiple sources — links to the originals are below.

The FBI disrupted infrastructure linked to a Chinese cyber espionage 'quartermaster' that provided reconnaissance, proxy management, and routing for attacks on U.S. critical infrastructure. Black Lotus Labs, Lumen Technologies' threat research arm, tracked the framework for a year and null-routed traffic to known infrastructure points. The service profiled and stole data from U.S. military, government, university, and corporate networks.
Key Facts
- The FBI disrupted infrastructure associated with a technical 'quartermaster' that provided reconnaissance, proxy management, and operational routing for Chinese cyber espionage.
- Black Lotus Labs, the threat research arm of Lumen Technologies, tracked the infrastructure for a year and null-routed traffic to known infrastructure points.
- The quartermaster service consisted of four components: QScan, Fast Labyrinth, QTRouter, and QTProxy.
- The infrastructure was used to profile and steal data from U.S. military, government, university, research, aerospace, bioinformatics, healthcare, financial, critical infrastructure, energy, and enterprise software organizations.
- Chinese threat actors have increasingly leveraged Operational Relay Box (ORB) networks since 2024 and intensified this activity earlier this year.
Quartermaster Infrastructure
The FBI disrupted infrastructure associated with a technical 'quartermaster' that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. Black Lotus Labs, the threat research arm of Lumen Technologies, tracked the infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure. The provider offers a reusable service consisting of four distinct operational elements: QScan, Fast Labyrinth, QTRouter, and QTProxy. QScan identifies and profiles high-value targets, collecting open ports, application banners, operating-system fingerprints, and configuration data. Fast Labyrinth is an encrypted relay network that conceals communications to and from victim organizations, while QTRouter provides a preconfigured physical device for access to proxy infrastructure and node management.
Targets and Impact
The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors. Lumen Technologies commended the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure. During the investigation, Black Lotus Labs shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact the nation's strategic assets. The researchers disrupted the infrastructure by null-routing traffic to known infrastructure points used by the quartermaster operators.
ORB Network Evolution
Lumen says the quartermaster industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators. ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used for relaying malicious traffic and obscuring its true source. Chinese threat actors have increasingly leveraged ORBs in cyber operations since 2024 and intensified this activity earlier this year. Instead of building a conventional ORB network from thousands of compromised devices, the quartermaster platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws. These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure.
1 source
FBI disrupts proxy network enabling Chinese espionage operations



