When advanced threat actors want to stay hidden, the infrastructure they use can matter as much as the tools for gaining access. For the past year, Black Lotus Labs® has tracked a key infrastructure provider supporting Chinese cyber espionage activities. Functioning as a “quartermaster,” its operations integrate reconnaissance, proxy orchestration and operational routing into a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.
Key findings
The quartermaster model depends on four connected components that work together to identify targets, route traffic and obscure operator activity. Each plays a different role in the broader enablement layer, turning reconnaissance, proxy access and traffic management into a repeatable service for downstream threat actors.
The quartermaster’s four main components are:
- “QScan”: Conducts reconnaissance to identify and profile high-value targets; networks discovered or profiled by QScan later appear in bidirectional communications through “Fast Labyrinth.”
- “Fast Labyrinth”: Provides the operational layer by co-opting commercial proxy infrastructure into an encrypted relay network that obfuscates traffic to and from target entities.
- “QTRouter”: Provides a preconfigured physical access device that manages operator and customer access to the proxy infrastructure and proxy node management system.
- “QTProxy”: Manages Fast Labyrinth operational nodes, allowing operators to use preconfigured relays or tailor unique paths to target entities.
- Together, these components streamline target discovery, communication routing and operational access, allowing Chinese espionage operators to conduct activities more efficiently while hiding their tracks.
Lumen commends the FBI and the U.S. Department of Justice (USDJ) for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure. As part of our investigation, Black Lotus Labs shared threat intelligence to warn U.S. government agencies of emerging risks to our nation’s strategic assets. We also null routed traffic to known infrastructure points used by the Quartermaster operators.
Research overview: shifting the focus to infrastructure brokers
Over the past few years, threat intelligence teams have noted a shift in the behavior of advanced persistent threat (APT) groups in relation to the infrastructure used for malicious activities. Rather than building and maintaining obfuscation networks from the ground up, their operations increasingly rely on shared, externally managed infrastructure to support campaigns such as those used by KV-botnet and Raptor Train.
Our research provides deeper visibility into one such case and identifies a private technical quartermaster that may originate from Nanjing, China. What we found suggests this entity provides specialized infrastructure and technical support that has been used by various Chinese threat actors. In this report, we introduce and examine what we describe as a “quartermaster” within cyber operations, an emerging but under-discussed role responsible for provisioning access, routing and obfuscation at scale for nation-state threat actors.
Rather than conducting direct intrusions, quartermaster operations facilitate complex obfuscation networks and distributed scanning frameworks, offering pre-packaged stealth, target verification telemetry and non-attributable transit layers to multiple consumers simultaneously. From a threat-hunting perspective, these shared networks represent a critical operational chokepoint: taking down a single quartermaster’s obfuscation network systematically degrades the capabilities of multiple active threat campaigns at once.
This report describes the architectural aspects of both the Fast Labyrinth network and the Qscan framework. Fast Labyrinth is made up of commercial consumer proxy architectures (“Airport”) and the QTRouter through which the operators access the QTProxy administrative control plane that manages Fast Labyrinth’s nodes. We present extensive telemetry from its global target mapping campaign and outline tactical defense strategies to counter this shared enablement tradecraft.
Understanding the operational relay box (ORB) ecosystem
To understand the mechanics of QTRouter/Fast Labyrinth, network defenders should first consider the broader evolution of state-aligned threat actor’s global operational networks.
As documented in recent joint cybersecurity advisories, including CISA's AA25-239A, advanced threat groups are rapidly moving away from static, attributable virtual private server (VPS) hosting providers. Instead, they increasingly rely on operational relay box (ORB) networks.
An ORB network is a decentralized mesh built from compromised or leased infrastructure, such as SOHO routers, IoT devices and rented VPSs. It routes malicious traffic through rotating IPs, blending with normal internet noise, and bypassing traditional defenses like IP blocklists and location-based policies.
The commercial "Airport" proxied transit layer: mechanics of Fast Labyrinth
The quartermaster has industrialized the construction of these ORB mesh networks by exploiting a unique structural loophole in commercial internet circumvention architectures: the Chinese "Airport" (机场/Jīchǎng) network ecosystem.
In mainland China's internet landscape, an "Airport" represents a commercial tiered subscription proxy service explicitly designed to bypass the “Great Firewall” (GFW). Unlike traditional consumer VPNs focused on personal anonymity, Airports operate as high-velocity international transit hubs and are managed via client software like Clash or Shadowrocket running specialized obfuscation protocols and optimized to disguise network traffic protocols (such as V2Ray, Shadowsocks and Trojan).
Rather than expending resources to compromise thousands of individual IoT devices to manually assemble a relay network, the quartermaster simply purchases high-tier corporate subscriptions to apex Airport networks. In this case, specifically “fastlink.ws.” This commercial co-opting grants the actor immediate access to ultra-low latency, high-bandwidth transit pipelines, such as dedicated International Private Leased Circuit (IPLC) channels and multi-homed BGP routing lanes.
Our tracking indicates that the quartermaster did not co-opt the entire fastlink.ws network. Instead, global IP backbone telemetry shows a highly deliberate selection process targeting specific, high-tier proxy egress nodes. Fast Labyrinth egress nodes, specifically those resolving to the unique flanycast-xxxx.yotocloud.com and flnode-xxxx.yotocloud.com subdomains, consistently initiate traffic targeting high-value networks. This outbound activity represents the definitive points where the proxy infrastructure was leveraged to interact directly with target environments.
While using this quartermaster’s pipeline, malicious state-sponsored traffic is seamlessly routed through the high-volume background noise of thousands of everyday consumers streaming media over the same premium egress nodes. Furthermore, because these commercial Airport node registries dynamically rotate and update via client subscription URLs, the underlying egress IP pool remains fluid, automatically bypassing static security defense perimeters.
Exposing the QTProxy/Fast Labyrinth admin plane: www.qtproxy.xyz
To access Fast Labyrinth proxies directly or the QTProxy node management system, quartermaster clients first authenticate through one of the QTRouter devices. From there, they can reach the primary administrative control hub that manages the co-opted proxy nodes, hosted on the domain qtproxy.xyz. The subdomain www.qtproxy.xyz serves as the “Proxy Node Management System” web panel console, used by operators to coordinate link paths and adjust traffic forwarding rules.
Further analysis and filtering of these administrative check-in logs over several months revealed a definitive structural loop connecting the developers directly to their infrastructure assets:
- Nanjing connections: Administrative check-in management activity observed from China Telecom and China Unicom IP space assigned to Nanjing, China. Although IP geolocation alone cannot determine the physical location of an operator, the activity provides additional geographic context for the infrastructure's administration
- The co-opted node linkage: Interlaced with the operator connections from Nanjing were matching sessions originating directly from explicit IPs resolving to the previously identified yotocloud.com subdomains.
We assess that this direct crossover highlights that the quartermaster’s master control portal was actively interacting with, testing and calibrating the co-opted fastlink.ws nodes used in the QTProxy/Fast Labyrinth network before leasing access out to downstream threat actors.
Fast Labyrinth operational dynamics: high-value sector targeting
Tracking Fast Labyrinth network traffic gave us a continuous window into downstream China-nexus operations. Rather than generating large traffic spikes or relying on noisy, indiscriminate automated scanning, the network patterns indicate a steady, precise focus on select targets. Downstream threat actors used these co-opted commercial routes to systematically profile and interact with target infrastructure on a global scale while remaining safely hidden within routine consumer network traffic.
An analysis of these communication paths highlights exactly how the threat actors manipulate this infrastructure to evade detection. The vast majority of the network's volume consists of routine traffic that closely mirrors that of an everyday commercial VPN user, allowing the actors to mask their footprint within the standard commercial transit noise. However, by filtering out this high-volume background noise, we find a targeted profiling campaign directed exclusively at specific strategic sectors.
Egress profiling reveals consistent telemetry stemming from major research universities worldwide. Their interests include advanced physics, bioinformatics, aerospace and satellite systems, as well as global government, defense and public sector networks. Fast Labyrinth traffic shows a focus on exposed development perimeters, unpatched cloud storage and credential theft. Operations target institutions to map networks and exploit open-sharing scientific research, especially in the U.S., U.K. and Asia-Pacific.
In the U.S., military and defense networks are heavily profiled, with a particular interest on active communication gateways, access control and the perimeters of suppliers managing sensitive logistics. Geologic and environmental agencies are also of interest, as are European infrastructure and judicial nodes worldwide.
Systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously.
Supporting capabilities: The QScan framework
To support its primary objectives, the quartermaster runs a secondary, completely decoupled target profiling utility called "QScan.” While the core proxy network focuses on managing stateful session paths, the QScan framework operates as the front-end scout. The architecture relies on an industrialized three-stage pipeline:
- The central task broker engine: Stationed at mq-task.qt-proxy.org (154.64.238[.]222), this hub manages centralized tracking and distribution using a combined Celery and RabbitMQ framework to stage targeting tasks.
- The distributed scanner fleet: Globally dispersed worker nodes execute scanning tasks, programmatically rotating across a pool of distinct /24 subnet blocks on a 30-day lifecycle to evade standard threshold detections.
- The central aggregation database backend: Worker nodes compress and stream discovered network metadata, including application banners, open port maps and configuration states, directly back to a high-performance Redis database server cluster hosted at mq-result.qt-proxy.org (154.64.238[.]247).
Behavioral profiling strategy: wide-spectrum mapping vs. precision interrogation
The quartermaster operations maintained a distinct two-track deployment strategy based on the target's nature.
1. Broad perimeter defense profiling
Against highly defended federal, intelligence and military allocations, the framework was deployed to run wide-spectrum perimeter defense profiling. The automated worker fleet ran continuous scanning sweeps across a number of U.S military networks.
Sweeps directed at these well-defended targets appeared to encounter rigid security filtering which often resulted in minimal feedback, however, the underlying pattern points to a long-term surface-mapping initiative. This quartermaster likely utilized these high-volume sweeps to evaluate defense perimeters, log active boundary interfaces, and catalog service and configuration drift over time across national defense interests and federal security program providers.
2. Targeted application interrogation loops
Beneath the footprint of their broad perimeter defense mapping were precision interrogation loops against highly specialized corporate, scientific, and infrastructure verticals. When interacting with these high-value entities, the broad scanning engine was suppressed. Instead, the workers deployed quiet, high-port application-layer version sweeps specifically tuned to extract operating system kernel fingerprints, identify edge trust boundaries, and map out responsive remote management interfaces.
Our long-term observation captured this precision engine as it built a library of high-value targets across several critical sectors that align with the Fast Labyrinth areas of focus. Worker nodes spent fewer cycles against U.S. military targets but were also tasked with healthcare, critical infrastructure, energy supply chains, financial services, and enterprise software repositories.
Closing the loop: the empirical target intersect
A key finding of this quartermaster enablement model is the intersection between the two separate networks. By comparing the independent QScan discoveries and the Fast Labyrinth operational sessions, our telemetry reveals a clear overlap from reconnaissance to direct interactions with target entities.
The QScan and Fast Labyrinth overlap
Our analysis revealed a structural connection between the automated profiling nodes (QScan) and the co-opted proxy network (Fast Labyrinth). Users of the quartermaster’s proxy nodes have been observed using Fast Labyrinth to reach a variety of targets; however, most high-value infrastructure sectors mapped or probed by QScan were later observed processing inbound connections from Fast Labyrinth proxies during the same tracking window. This alignment across identical destination networks indicates that the scanning framework and the transit network are structurally tethered to the same operational objectives; however, our telemetry shows they may also be used independently by the quartermaster’s customers.
The transition to probable exploitation
While the vast majority of the quartermaster’s traffic on QScan consists of single-packet reconnaissance probes, the presence of stable, high-bandwidth bidirectional sessions with targeted research and infrastructure nodes marks a critical pivot. Once a potential target interface was confirmed, the operator transitioned from broad probing to attempted exploitation, routing interactive communication sessions back through the obfuscated Fast Labyrinth proxy mesh to move laterally, maintain persistent backchannels or harvest proprietary data from the very same machines their scouts flagged.
What shared cyber infrastructure means for enterprise defense
The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations. By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale. Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat.
To secure enterprise boundaries against this type of highly obfuscated tradecraft, Black Lotus Labs recommends the following:
- Implement CISA and NCSC guidance for mitigating activity from State-sponsored actors and defending against China-nexus covert networks of compromised devices.
- Adopt comprehensive Secure Access Service Edge (SASE) or similar solutions to reduce external attack surface.
- Follow best practices for routers, firewalls and IoT devices, such as regularly rebooting and installing security updates and patches.
Technical indicators of compromise (IoCs): master infrastructure artifact matrix:
Domain
qtproxy.xyz
Fast Labyrinth admin plane
Primary administrative domain for proxy orchestration
Subdomain
www.qtproxy.xyz
Fast Labyrinth admin plane
Mapped to IP 1.32.216[.]171 - main target for Go-http-client logins
Domain
qt-proxy.org
Fast Labyrinth core
Active infrastructure element deployed to replace legacy qt-team.com assets
Subdomain
jump.qt-proxy.org
Fast Labyrinth core
Mapped to IP 8.148.149[.]147 - active operational jump box
Domain
instantmessagehub.tech
Fast Labyrinth core
Mapped to IP 47.76.131[.]175 - highly probable administrative interface endpoint
Subdomain
mq-task-qt-team.com
QScan broker
Mapped to IP 154.64.238[.]222 - central RabbitMQ task engine
Subdomain
mq-result-qt-team.com
QScan backend
Mapped to IP 154.64.238[.]247 - central Redis results database server
Native commercial application egress indicators:
Network defenders evaluating historical netflow logs or DNS query files should audit for anomalous outbound or bidirectional traffic loops reaching out to the following subdomains on the root domain yotocloud.com, which represent the underlying commercial fastlink.ws transit nodes co-opted by the quartermaster:
- flanycast-us.yotocloud.com / flanycast-us-bak.yotocloud.com
- flanycast-hk.yotocloud.com / flanycast-hk-bak.yotocloud.com
- flanycast-jp.yotocloud.com
- flanycast-tw.yotocloud.com
- flanycast-sg.yotocloud.com
- flnode-ulus.yotocloud.com
- flnode-dl.yotocloud.com
Explore additional threat resources
Review these current IOCs and visit our GitHub page, which we update continuously.
For broader threat protection and insights, explore these resources:
- Learn how we help protect customers with Lumen DefenderSM.
- Read the Lumen Defender Threatscape Report to understand how modern cyberthreats are evolving.
- Collaborate with us on similar research by reaching out on LinkedIn or X (@BlackLotusLabs).
Analysis of this Infrastructure Quartermaster was performed by Damon Rouse and Steve Rudd, with technical editing by Ryan English and Mike Horka.
Stay ahead of evolving nation-state threats with intelligence from the researchers tracking them in real time. Explore Black Lotus Labs for the latest threat research, technical analysis and insights to help strengthen enterprise defense.
This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided "as is" without any warranty or condition of any kind, either express or implied. Use of this information is at the end user's own risk. Lumen does not warrant that the information will meet the end user's requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.