FBI Pulls Plug on Chinese Espionage 'Quartermaster' That Rented Out Hacking Kit
A commercial-style service sold reconnaissance, proxy routing, and relay networks to China-linked spies targeting US critical infrastructure. Lumen's Black Lotus Labs helped map it.

Key points
- The FBI has disrupted a shared hacking service, described as a technical "quartermaster," that supplied Chinese state-linked spies with reconnaissance and traffic-hiding tools.
- Lumen Technologies' Black Lotus Labs tracked the operation for a year and found four distinct components: QScan, Fast Labyrinth, QTRouter, and QTProxy.
- Victims spanned US military and defense bodies, government networks, universities, aerospace, healthcare, finance, energy, and enterprise software vendors.
- The relay network, Fast Labyrinth, rented premium nodes from Chinese commercial proxy service fastlink.ws to mix spy traffic with normal consumer proxy traffic.
- Lumen null-routed traffic to known infrastructure points, but warns that static IP blocking will not hold because the proxies rotate constantly.
The FBI has knocked over the plumbing behind a shared hacking service that let Chinese cyber-espionage crews scout US targets and hide where their traffic came from.
Researchers at Black Lotus Labs, the threat intelligence arm of Lumen Technologies, spent a year mapping the setup. They call the operator a "quartermaster," a military term for the person who hands out kit and supplies. In this case the kit was a ready-made hacking toolchain that different Chinese spy teams could rent and reuse.
The story was first reported by BleepingComputer.
What did the service actually do?
It sold hacking-as-a-service. Four separate tools handled the different jobs a spy crew needs: finding targets, hiding traffic, plugging into the relay network, and steering routes through it.
Here is how the pieces fit together.
| Component | Job it does |
|---|---|
| QScan | Scans the internet for interesting targets, noting open ports, software versions, and how systems are set up |
| Fast Labyrinth | An encrypted relay network that hides who is really talking to the victim |
| QTRouter | A pre-built physical box that connects an operator to the proxy network |
| QTProxy | Software for picking relays and building custom routes through Fast Labyrinth |
Crucially, Black Lotus Labs saw the same organisations that QScan had profiled turning up later as targets contacted through Fast Labyrinth. That link between scouting and follow-up attacks is the strongest sign this was one joined-up operation, not a coincidence.
Who was targeted?
Mostly high-value US organisations. The list reads like a shopping catalogue for a foreign intelligence service: military and defence bodies, federal and state government networks, universities and research institutes, aerospace firms, bioinformatics labs, hospitals and healthcare providers, banks, energy and other critical infrastructure operators, and companies that sell business software.
Lumen believes the two-way connections it observed through the proxy network point to attempted break-ins, movement between internal systems, planting long-term access, or quietly stealing data.
How was the network hidden?
Through a technique called an ORB, or Operational Relay Box network. An ORB is a scattered web of hacked home routers, internet-connected devices, rented virtual servers, and commercial proxy services. Traffic bounces through it so investigators cannot easily see where an attack really started.
Chinese operators have leaned on ORBs heavily since 2024, and stepped it up this year. The quartermaster took a shortcut: instead of building an ORB from thousands of infected home devices, it simply bought premium access to nodes run by a Chinese commercial proxy provider called fastlink.ws. Spy traffic then flowed through the same pipes as ordinary customers using the proxy service, which made it much harder to spot.
What did Lumen and the FBI do about it?
Lumen null-routed the traffic, meaning it sent packets aimed at known quartermaster infrastructure into a dead end on its network. The FBI and Department of Justice took separate action against the wider operation.
Lumen is honest about the limits. Because the service constantly rotates through commercial proxy nodes, blocking a static list of IP addresses will not keep up. Defenders should follow CISA and NCSC guidance on China-linked intrusions, and keep routers, firewalls, and internet-connected devices patched and properly configured. Multi-factor authentication would not have stopped the reconnaissance stage, but on the follow-up intrusions it remains one of the few controls that reliably breaks stolen-credential attacks.
Should ordinary people worry?
Not directly. This was espionage aimed at institutions, not consumer accounts. But if you work in one of the sectors named above, assume your employer is on somebody's list, and treat unexpected login prompts and password-reset emails with more suspicion than usual.



