hero-background-color-red-orange-gradient
image
https://assets.lumen.com/is/image/Lumen/img-blog-hero-BLL-QM?Creativeid=7b31ce8d-ce3d-42e8-8cf1-cdcc94b62849
https://assets.lumen.com/is/image/Lumen/img-blog-hero-BLL-QM?Creativeid=7b31ce8d-ce3d-42e8-8cf1-cdcc94b62849
https://assets.lumen.com/is/image/Lumen/img-blog-hero-BLL-QM?Creativeid=7b31ce8d-ce3d-42e8-8cf1-cdcc94b62849
A view of a large supply warehouse named "Proxy Supply ltd." The warehouse looks well maintained, there is a flagpole in the parking lot with the symbol of a typhoon on the flag
content
content-col-11
The infrastructure quartermaster: inside a China-nexus state enablement model

When advanced threat actors want to stay hidden, the infrastructure they use can matter as much as the tools for gaining access. For the past year, Black Lotus Labs® has tracked a key infrastructure provider supporting Chinese cyber espionage activities. Functioning as a “quartermaster,” its operations integrate reconnaissance, proxy orchestration and operational routing into a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.

Key findings

The quartermaster model depends on four connected components that work together to identify targets, route traffic and obscure operator activity. Each plays a different role in the broader enablement layer, turning reconnaissance, proxy access and traffic management into a repeatable service for downstream threat actors.

The quartermaster’s four main components are:

Lumen commends the FBI and the U.S. Department of Justice (USDJ) for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure. As part of our investigation, Black Lotus Labs shared threat intelligence to warn U.S. government agencies of emerging risks to our nation’s strategic assets. We also null routed traffic to known infrastructure points used by the Quartermaster operators.

Research overview: shifting the focus to infrastructure brokers

Over the past few years, threat intelligence teams have noted a shift in the behavior of advanced persistent threat (APT) groups in relation to the infrastructure used for malicious activities. Rather than building and maintaining obfuscation networks from the ground up, their operations increasingly rely on shared, externally managed infrastructure to support campaigns such as those used by KV-botnet and Raptor Train.

Our research provides deeper visibility into one such case and identifies a private technical quartermaster that may originate from Nanjing, China. What we found suggests this entity provides specialized infrastructure and technical support that has been used by various Chinese threat actors. In this report, we introduce and examine what we describe as a “quartermaster” within cyber operations, an emerging but under-discussed role responsible for provisioning access, routing and obfuscation at scale for nation-state threat actors.

Rather than conducting direct intrusions, quartermaster operations facilitate complex obfuscation networks and distributed scanning frameworks, offering pre-packaged stealth, target verification telemetry and non-attributable transit layers to multiple consumers simultaneously. From a threat-hunting perspective, these shared networks represent a critical operational chokepoint: taking down a single quartermaster’s obfuscation network systematically degrades the capabilities of multiple active threat campaigns at once.

This report describes the architectural aspects of both the Fast Labyrinth network and the Qscan framework. Fast Labyrinth is made up of commercial consumer proxy architectures (“Airport”) and the QTRouter through which the operators access the QTProxy administrative control plane that manages Fast Labyrinth’s nodes. We present extensive telemetry from its global target mapping campaign and outline tactical defense strategies to counter this shared enablement tradecraft.

https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-1?Creativeid=d3fef837-4891-414b-ba39-4d6d8ab40a5e
https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-1?Creativeid=d3fef837-4891-414b-ba39-4d6d8ab40a5e
https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-1?Creativeid=d3fef837-4891-414b-ba39-4d6d8ab40a5e
Overview of the various elements that comprise the Quartermaster's system. This shows the clients logging into the QTRouter and able to reach into the proxy node management, move into Fast Labyrinth nodes, and proceed to intended victims
Figure 1: Elements of Quartermaster operations

Understanding the operational relay box (ORB) ecosystem

To understand the mechanics of QTRouter/Fast Labyrinth, network defenders should first consider the broader evolution of state-aligned threat actor’s global operational networks.

As documented in recent joint cybersecurity advisories, including CISA's AA25-239A, advanced threat groups are rapidly moving away from static, attributable virtual private server (VPS) hosting providers. Instead, they increasingly rely on operational relay box (ORB) networks.

An ORB network is a decentralized mesh built from compromised or leased infrastructure, such as SOHO routers, IoT devices and rented VPSs. It routes malicious traffic through rotating IPs, blending with normal internet noise, and bypassing traditional defenses like IP blocklists and location-based policies.

The commercial "Airport" proxied transit layer: mechanics of Fast Labyrinth

The quartermaster has industrialized the construction of these ORB mesh networks by exploiting a unique structural loophole in commercial internet circumvention architectures: the Chinese "Airport" (机场/Jīchǎng) network ecosystem.

In mainland China's internet landscape, an "Airport" represents a commercial tiered subscription proxy service explicitly designed to bypass the “Great Firewall” (GFW). Unlike traditional consumer VPNs focused on personal anonymity, Airports operate as high-velocity international transit hubs and are managed via client software like Clash or Shadowrocket running specialized obfuscation protocols and optimized to disguise network traffic protocols (such as V2Ray, Shadowsocks and Trojan).

Rather than expending resources to compromise thousands of individual IoT devices to manually assemble a relay network, the quartermaster simply purchases high-tier corporate subscriptions to apex Airport networks. In this case, specifically “fastlink.ws.” This commercial co-opting grants the actor immediate access to ultra-low latency, high-bandwidth transit pipelines, such as dedicated International Private Leased Circuit (IPLC) channels and multi-homed BGP routing lanes.

Our tracking indicates that the quartermaster did not co-opt the entire fastlink.ws network. Instead, global IP backbone telemetry shows a highly deliberate selection process targeting specific, high-tier proxy egress nodes. Fast Labyrinth egress nodes, specifically those resolving to the unique flanycast-xxxx.yotocloud.com and flnode-xxxx.yotocloud.com subdomains, consistently initiate traffic targeting high-value networks. This outbound activity represents the definitive points where the proxy infrastructure was leveraged to interact directly with target environments.

While using this quartermaster’s pipeline, malicious state-sponsored traffic is seamlessly routed through the high-volume background noise of thousands of everyday consumers streaming media over the same premium egress nodes. Furthermore, because these commercial Airport node registries dynamically rotate and update via client subscription URLs, the underlying egress IP pool remains fluid, automatically bypassing static security defense perimeters.

Exposing the QTProxy/Fast Labyrinth admin plane: www.qtproxy.xyz

To access Fast Labyrinth proxies directly or the QTProxy node management system, quartermaster clients first authenticate through one of the QTRouter devices. From there, they can reach the primary administrative control hub that manages the co-opted proxy nodes, hosted on the domain qtproxy.xyz. The subdomain www.qtproxy.xyz serves as the “Proxy Node Management System” web panel console, used by operators to coordinate link paths and adjust traffic forwarding rules.

Further analysis and filtering of these administrative check-in logs over several months revealed a definitive structural loop connecting the developers directly to their infrastructure assets:

We assess that this direct crossover highlights that the quartermaster’s master control portal was actively interacting with, testing and calibrating the co-opted fastlink.ws nodes used in the QTProxy/Fast Labyrinth network before leasing access out to downstream threat actors.

Fast Labyrinth operational dynamics: high-value sector targeting

Tracking Fast Labyrinth network traffic gave us a continuous window into downstream China-nexus operations. Rather than generating large traffic spikes or relying on noisy, indiscriminate automated scanning, the network patterns indicate a steady, precise focus on select targets. Downstream threat actors used these co-opted commercial routes to systematically profile and interact with target infrastructure on a global scale while remaining safely hidden within routine consumer network traffic.

An analysis of these communication paths highlights exactly how the threat actors manipulate this infrastructure to evade detection. The vast majority of the network's volume consists of routine traffic that closely mirrors that of an everyday commercial VPN user, allowing the actors to mask their footprint within the standard commercial transit noise. However, by filtering out this high-volume background noise, we find a targeted profiling campaign directed exclusively at specific strategic sectors.

Egress profiling reveals consistent telemetry stemming from major research universities worldwide. Their interests include advanced physics, bioinformatics, aerospace and satellite systems, as well as global government, defense and public sector networks. Fast Labyrinth traffic shows a focus on exposed development perimeters, unpatched cloud storage and credential theft. Operations target institutions to map networks and exploit open-sharing scientific research, especially in the U.S., U.K. and Asia-Pacific.

In the U.S., military and defense networks are heavily profiled, with a particular interest on active communication gateways, access control and the perimeters of suppliers managing sensitive logistics. Geologic and environmental agencies are also of interest, as are European infrastructure and judicial nodes worldwide.

Systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously.

Supporting capabilities: The QScan framework

To support its primary objectives, the quartermaster runs a secondary, completely decoupled target profiling utility called "QScan.” While the core proxy network focuses on managing stateful session paths, the QScan framework operates as the front-end scout. The architecture relies on an industrialized three-stage pipeline:

https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-4?Creativeid=3dd47bfb-93d3-41e1-b207-d10d174d967b
https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-4?Creativeid=3dd47bfb-93d3-41e1-b207-d10d174d967b
https://assets.lumen.com/is/image/Lumen/img-blog-BLL-QM-4?Creativeid=3dd47bfb-93d3-41e1-b207-d10d174d967b
Order of operations for the QScan framework, showing the operator working through the central task broker engine to organize the fleet of scanners, the data returned by those scanners lands in a database to be used by the operators and inform their customers
Figure 4: The QScan information pipeline

Behavioral profiling strategy: wide-spectrum mapping vs. precision interrogation

The quartermaster operations maintained a distinct two-track deployment strategy based on the target's nature.

1. Broad perimeter defense profiling

Against highly defended federal, intelligence and military allocations, the framework was deployed to run wide-spectrum perimeter defense profiling. The automated worker fleet ran continuous scanning sweeps across a number of U.S military networks.

Sweeps directed at these well-defended targets appeared to encounter rigid security filtering which often resulted in minimal feedback, however, the underlying pattern points to a long-term surface-mapping initiative. This quartermaster likely utilized these high-volume sweeps to evaluate defense perimeters, log active boundary interfaces, and catalog service and configuration drift over time across national defense interests and federal security program providers.

2. Targeted application interrogation loops

Beneath the footprint of their broad perimeter defense mapping were precision interrogation loops against highly specialized corporate, scientific, and infrastructure verticals. When interacting with these high-value entities, the broad scanning engine was suppressed. Instead, the workers deployed quiet, high-port application-layer version sweeps specifically tuned to extract operating system kernel fingerprints, identify edge trust boundaries, and map out responsive remote management interfaces.

Our long-term observation captured this precision engine as it built a library of high-value targets across several critical sectors that align with the Fast Labyrinth areas of focus. Worker nodes spent fewer cycles against U.S. military targets but were also tasked with healthcare, critical infrastructure, energy supply chains, financial services, and enterprise software repositories.

Closing the loop: the empirical target intersect

A key finding of this quartermaster enablement model is the intersection between the two separate networks. By comparing the independent QScan discoveries and the Fast Labyrinth operational sessions, our telemetry reveals a clear overlap from reconnaissance to direct interactions with target entities.

The QScan and Fast Labyrinth overlap

Our analysis revealed a structural connection between the automated profiling nodes (QScan) and the co-opted proxy network (Fast Labyrinth). Users of the quartermaster’s proxy nodes have been observed using Fast Labyrinth to reach a variety of targets; however, most high-value infrastructure sectors mapped or probed by QScan were later observed processing inbound connections from Fast Labyrinth proxies during the same tracking window. This alignment across identical destination networks indicates that the scanning framework and the transit network are structurally tethered to the same operational objectives; however, our telemetry shows they may also be used independently by the quartermaster’s customers.

The transition to probable exploitation

While the vast majority of the quartermaster’s traffic on QScan consists of single-packet reconnaissance probes, the presence of stable, high-bandwidth bidirectional sessions with targeted research and infrastructure nodes marks a critical pivot. Once a potential target interface was confirmed, the operator transitioned from broad probing to attempted exploitation, routing interactive communication sessions back through the obfuscated Fast Labyrinth proxy mesh to move laterally, maintain persistent backchannels or harvest proprietary data from the very same machines their scouts flagged.

What shared cyber infrastructure means for enterprise defense

The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations. By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale. Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat.

To secure enterprise boundaries against this type of highly obfuscated tradecraft, Black Lotus Labs recommends the following:

Technical indicators of compromise (IoCs): master infrastructure artifact matrix:

Domain
qtproxy.xyz
Fast Labyrinth admin plane
Primary administrative domain for proxy orchestration

Subdomain
www.qtproxy.xyz
Fast Labyrinth admin plane
Mapped to IP 1.32.216[.]171 - main target for Go-http-client logins

Domain
qt-proxy.org
Fast Labyrinth core
Active infrastructure element deployed to replace legacy qt-team.com assets

Subdomain
jump.qt-proxy.org
Fast Labyrinth core
Mapped to IP 8.148.149[.]147 - active operational jump box

Domain
instantmessagehub.tech
Fast Labyrinth core
Mapped to IP 47.76.131[.]175 - highly probable administrative interface endpoint

Subdomain
mq-task-qt-team.com
QScan broker
Mapped to IP 154.64.238[.]222 - central RabbitMQ task engine

Subdomain
mq-result-qt-team.com
QScan backend
Mapped to IP 154.64.238[.]247 - central Redis results database server

Native commercial application egress indicators:

Network defenders evaluating historical netflow logs or DNS query files should audit for anomalous outbound or bidirectional traffic loops reaching out to the following subdomains on the root domain yotocloud.com, which represent the underlying commercial fastlink.ws transit nodes co-opted by the quartermaster:

Explore additional threat resources

Review these current IOCs and visit our GitHub page, which we update continuously.

For broader threat protection and insights, explore these resources:

Analysis of this Infrastructure Quartermaster was performed by Damon Rouse and Steve Rudd, with technical editing by Ryan English and Mike Horka.

Stay ahead of evolving nation-state threats with intelligence from the researchers tracking them in real time. Explore Black Lotus Labs for the latest threat research, technical analysis and insights to help strengthen enterprise defense.

This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided "as is" without any warranty or condition of any kind, either express or implied. Use of this information is at the end user's own risk. Lumen does not warrant that the information will meet the end user's requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.

image
https://assets.lumen.com/is/image/Lumen/author-black-lotus-labs-logo-image-300x300?$PNG$&Creativeid=b08a9660-2840-4cf8-b2b4-aa45b9585632
https://assets.lumen.com/is/image/Lumen/author-black-lotus-labs-logo-image-300x300?$PNG$&Creativeid=b08a9660-2840-4cf8-b2b4-aa45b9585632
https://assets.lumen.com/is/image/Lumen/author-black-lotus-labs-logo-image-300x300?$PNG$&Creativeid=b08a9660-2840-4cf8-b2b4-aa45b9585632
The Black Lotus Labs logo showing the name in black lettering with an image of a black lotus flower to the right.
content
Author

Black Lotus Labs

The mission of Black Lotus Labs® is to leverage our network visibility to help protect customers and keep the internet clean.