FBI Pulls Plug on Chinese Espionage 'Quartermaster' That Rented Out Hacking Kit
A commercial-style service sold reconnaissance, proxy routing, and relay networks to China-linked spies targeting US critical infrastructure. Lumen's Black Lotus Labs spent a year mapping it.

Key points
- The FBI has disrupted a shared hacking service, described as a technical "quartermaster," that supplied Chinese state-linked spies with reconnaissance and traffic-hiding tools.
- Lumen Technologies' Black Lotus Labs tracked the operation for a year and found four distinct components: QScan, Fast Labyrinth, QTRouter, and QTProxy.
- Victims spanned US military and defence bodies, government networks, universities, aerospace, healthcare, financial firms, energy companies, and enterprise software vendors.
- The relay network, Fast Labyrinth, rented premium nodes from Chinese commercial proxy service fastlink.ws to mix spy traffic with ordinary consumer proxy traffic.
- Lumen null-routed traffic to known infrastructure points, but warns that static IP blocking won't hold because the proxies rotate constantly.
The FBI has knocked over the plumbing behind a shared hacking service that let Chinese cyber-espionage crews scout US targets and hide where their traffic came from.
Researchers at Black Lotus Labs, the threat intelligence arm of Lumen Technologies, spent a year mapping the setup. They call the operator a "quartermaster," a military term for the person who hands out kit and supplies. Here the kit was a ready-made hacking toolchain that different Chinese spy teams could rent and reuse. The story was first reported by BleepingComputer.
What did the service actually do?
It sold hacking-as-a-service. Four separate tools handled the different jobs a spy crew needs: finding targets, hiding traffic, plugging into the relay network, and steering routes through it.
| Component | Job it does |
|---|---|
| QScan | Scans the internet for targets, noting open ports, software versions, and system configuration |
| Fast Labyrinth | An encrypted relay network that hides who is really talking to the victim |
| QTRouter | A pre-built physical box that connects an operator to the proxy network |
| QTProxy | Software for picking relays and building custom routes through Fast Labyrinth |
Black Lotus Labs saw the same organisations that QScan had profiled turning up later as targets contacted through Fast Labyrinth. That link between scouting and follow-up attacks is the strongest sign this was one joined-up operation.
Who was targeted?
Mostly high-value US organisations. The list reads like a shopping catalogue for a foreign intelligence service: military and defence bodies, federal and state government networks, universities, aerospace firms, bioinformatics labs, healthcare providers, banks, energy operators, and enterprise software vendors.
Lumen assessed that two-way connections it observed through the proxy network likely represent attempted break-ins, lateral movement between internal systems, or quiet data theft.
How was the network hidden?
Through a technique called an ORB, or Operational Relay Box network. An ORB is a scattered web of hacked home routers, internet-connected devices, rented virtual servers, and commercial proxy services. Traffic bounces through it so investigators can't easily trace where an attack started.
Chinese operators have leaned on ORBs heavily since 2024 and stepped it up this year. We first covered the tactic on 26 August 2026. The quartermaster took a shortcut: instead of building an ORB from thousands of infected home devices, it bought premium access to nodes run by Chinese commercial proxy provider fastlink.ws. Spy traffic then flowed through the same pipes as ordinary customers, which made it much harder to spot.
What did Lumen and the FBI do about it?
Lumen null-routed the traffic, sending packets aimed at known quartermaster infrastructure into a dead end on its network. The FBI and Department of Justice took separate action against the wider operation.
Lumen is honest about the limits. Because the service constantly rotates through commercial proxy nodes, blocking a static list of IP addresses won't keep up. Defenders should follow CISA and NCSC guidance on China-linked intrusions and keep routers, firewalls, and internet-connected devices patched and properly configured. Multi-factor authentication wouldn't have stopped the reconnaissance stage, but against the follow-up intrusions it remains one of the few controls that reliably breaks stolen-credential attacks.
This disruption fits a pattern that's been building fast. Since 13 August alone, we've reported on the Jewelbug hacker-for-hire group, a signed Windows rootkit used by Mustang Panda, and DOJ seizures tied to a Chinese espionage front. The quartermaster model is the supply-chain layer underneath all of it.
Should ordinary people worry?
Not directly. This was espionage aimed at institutions, not consumer accounts. But if you work in one of the sectors named above, assume your employer is on somebody's list, and treat unexpected login prompts and password-reset emails with more suspicion than usual.



