Skip to content
The Infrastructure Quartermaster Inside A China Nexus State Enablement Model

The Infrastructure Quartermaster Inside A China Nexus State Enablement Model

www.lumen.com August 27, 2026

When advanced threat actors want to stay hidden, the infrastructure they use can matter as much as the tools for gaining access. For the past year, Black Lotus Labs® has tracked a key infrastructure provider supporting Chinese cyber espionage activities. Functioning as a “quartermaster,” its operations integrate reconnaissance, proxy orchestration and operational routing into a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.

The quartermaster model depends on four connected components that work together to identify targets, route traffic and obscure operator activity. Each plays a different role in the broader enablement layer, turning reconnaissance, proxy access and traffic management into a repeatable service for downstream threat actors.

The quartermaster’s four main components are:

Lumen commends the FBI and the U.S. Department of Justice (USDJ) for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure. As part of our investigation, Black Lotus Labs shared threat intelligence to warn U.S. government agencies of emerging risks to our nation’s strategic assets. We also null routed traffic to known infrastructure points used by the Quartermaster operators.

Over the past few years, threat intelligence teams have noted a shift in the behavior of advanced persistent threat (APT) groups in relation to the infrastructure used for malicious activities. Rather than building and maintaining obfuscation networks from the ground up, their operations increasingly rely on shared, externally managed infrastructure to support campaigns such as those used by KV-botnet and Raptor Train.

Our research provides deeper visibility into one such case and identifies a private technical quartermaster that may originate from Nanjing, China. What we found suggests this entity provides specialized infrastructure and technical support that has been used by various Chinese threat actors . In this report, we introduce and examine what we describe as a “quartermaster” within cyber operations, an emerging but under-discussed role responsible for provisioning access, routing and obfuscation at scale for nation-state threat actors.

Rather than conducting direct intrusions, quartermaster operations facilitate complex obfuscation networks and distributed scanning frameworks, offering pre-packaged stealth, target verification telemetry and non-attributable transit layers to multiple consumers simultaneously. From a threat-hunting perspective, these shared networks represent a critical operational chokepoint: taking down a single quartermaster’s obfuscation network systematically degrades the capabilities of multiple active threat campaigns at once.

This report describes the architectural aspects of both the Fast Labyrinth network and the Qscan framework. Fast Labyrinth is made up of commercial consumer proxy architectures (“Airport”) and the QTRouter through which the operators access the QTProxy administrative control plane that manages Fast Labyrinth’s nodes. We present extensive telemetry from its global target mapping campaign and outline tactical defense strategies to counter this shared enablement tradecraft.

To understand the mechanics of QTRouter/Fast Labyrinth, network defenders should first consider the broader evolution of state-aligned threat actor’s global operational networks.

As documented in recent joint cybersecurity advisories, including CISA's AA25-239A , advanced threat groups are rapidly moving away from static, attributable virtual private server (VPS) hosting providers. Instead, they increasingly rely on operational relay box (ORB) networks.

An ORB network is a decentralized mesh built from compromised or leased infrastructure, such as SOHO routers, IoT devices and rented VPSs. It routes malicious traffic through rotating IPs, blending with normal internet noise, and bypassing traditional defenses like IP blocklists and location-based policies.

The quartermaster has industrialized the construction of these ORB mesh networks by exploiting a unique structural loophole in commercial internet circumvention architectures: the Chinese "Airport" (机场/Jīchǎng) network ecosystem.

In mainland China's internet landscape, an "Airport" represents a commercial tiered subscription proxy service explicitly designed to bypass the “ Great Firewall ” (GFW). Unlike traditional consumer VPNs focused on personal anonymity, Airports operate as high-velocity international transit hubs and are managed via client software like Clash or Shadowrocket running specialized obfuscation protocols and optimized to disguise network traffic protocols (such as V2Ray, Shadowsocks and Trojan).

Rather than expending resources to compromise thousands of individual IoT devices to manually assemble a relay network, the quartermaster simply purchases high-tier corporate subscriptions to apex Airport networks. In this case, specifically “fastlink.ws.” This commercial co-opting grants the actor immediate access to ultra-low latency, high-bandwidth transit pipelines, such as dedicated International Private Leased Circuit (IPLC) channels and multi-homed BGP routing lanes.

Our tracking indicates that the quartermaster did not co-opt the entire fastlink.ws network. Instead, global IP backbone telemetry shows a highly deliberate selection process targeting specific, high-tier proxy egress nodes. Fast Labyrinth egress nodes, specifically those resolving to the unique flanycast-xxxx.yotocloud.com and flnode-xxxx.yotocloud.com subdomains, consistently initiate traffic targeting high-value networks. This outbound activity represents the definitive points where the proxy infrastructure was leveraged to interact directly with target environments.

While using this quartermaster’s pipeline, malicious state- traffic is seamlessly routed through the high-volume background noise of thousands of everyday consumers streaming media over the same premium egress nodes. Furthermore, because these commercial Airport node registries dynamically rotate and update via client subscription URLs, the underlying egress IP pool remains fluid, automatically bypassing static security defense perimeters.

To access Fast Labyrinth proxies directly or the QTProxy node management system, quartermaster clients first authenticate through one of the QTRouter devices. From there, they can reach the primary administrative control hub that manages the co-opted proxy nodes, hosted on the domain qtproxy.xyz . The subdomain serves as the “Proxy Node Management System” web panel console, used by operators to coordinate link paths and adjust traffic forwarding rules.

Further analysis and filtering of these administrative check-in logs over several months revealed a definitive structural loop connecting the developers directly to their infrastructure assets:

We assess that this direct crossover highlights that the quartermaster’s master control portal was actively interacting with, testing and calibrating the co-opted fastlink.ws nodes used in the QTProxy/Fast Labyrinth network before leasing access out to downstream threat actors.

Tracking Fast Labyrinth network traffic gave us a continuous window into downstream China-nexus operations. Rather than generating large traffic spikes or relying on noisy, indiscriminate automated scanning, the network patterns indicate a steady, precise focus on select targets. Downstream threat actors used these co-opted commercial routes to systematically profile and interact with target infrastructure on a global scale while remaining safely hidden within routine consumer network traffic.

An analysis of these communication paths highlights exactly how the threat actors manipulate this infrastructure to evade detection. The vast majority of the network's volume consists of routine traffic that closely mirrors that of an everyday commercial VPN user, allowing the actors to mask their footprint within the standard commercial transit noise. However, by filtering out this high-volume background noise, we find a targeted profiling campaign directed exclusively at specific strategic sectors.

Egress profiling reveals consistent telemetry stemming from major research universities worldwide. Their interests include advanced physics, bioinformatics, aerospace and satellite systems, as well as global government, defense and public sector networks. Fast Labyrinth traffic shows a focus on exposed development perimeters, unpatched cloud storage and credential theft. Operations target institutions to map networks and exploit open-sharing scientific research, especially in the U.S., U.K. and Asia-Pacific.

In the U.S., military and defense networks are heavily profiled, with a particular interest on active communication gateways, access control and the perimeters of suppliers managing sensitive logistics. Geologic and environmental agencies are also of interest, as are European infrastructure and judicial nodes worldwide.

Systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously.

To support its primary objectives, the quartermaster runs a secondary, completely decoupled target profiling utility called "QScan.” While the core proxy network focuses on managing stateful session paths, the QScan framework operates as the front-end scout. The architecture relies on an industrialized three-stage pipeline:

The quartermaster operations maintained a distinct two-track deployment strategy based on the target's nature.

Against highly defended federal, intelligence and military allocations, the framework was deployed to run wide-spectrum perimeter defense profiling. The automated worker fleet ran continuous scanning sweeps across a number of U.S military networks.

Sweeps directed at these well-defended targets appeared to encounter rigid security filtering which often resulted in minimal feedback, however, the underlying pattern points to a long-term surface-mapping initiative. This quartermaster likely utilized these high-volume sweeps to evaluate defense perimeters, log active boundary interfaces, and catalog service and configuration drift over time across national defense interests and federal security program providers.

Beneath the footprint of their broad perimeter defense mapping were precision interrogation loops against highly specialized corporate, scientific, and infrastructure verticals. When interacting with these high-value entities, the broad scanning engine was suppressed. Instead, the workers deployed quiet, high-port application-layer version sweeps specifically tuned to extract operating system kernel fingerprints, identify edge trust boundaries, and map out responsive remote management interfaces.

Our long-term observation captured this precision engine as it built a library of high-value targets across several critical sectors that align with the Fast Labyrinth areas of focus. Worker nodes spent fewer cycles against U.S. military targets but were also tasked with healthcare, critical infrastructure, energy supply chains, financial services, and enterprise software repositories.

A key finding of this quartermaster enablement model is the intersection between the two separate networks. By comparing the independent QScan discoveries and the Fast Labyrinth operational sessions, our telemetry reveals a clear overlap from reconnaissance to direct interactions with target entities.

Our analysis revealed a structural connection between the automated profiling nodes (QScan) and the co-opted proxy network (Fast Labyrinth). Users of the quartermaster’s proxy nodes have been observed using Fast Labyrinth to reach a variety of targets; however, most high-value infrastructure sectors mapped or probed by QScan were later observed processing inbound connections from Fast Labyrinth proxies during the same tracking window. This alignment across identical destination networks indicates that the scanning framework and the transit network are structurally tethered to the same operational objectives; however, our telemetry shows they may also be used independently by the quartermaster’s customers. The transition to probable exploitation

While the vast majority of the quartermaster’s traffic on QScan consists of single-packet reconnaissance probes, the presence of stable, high-bandwidth bidirectional sessions with targeted research and infrastructure nodes marks a critical pivot. Once a potential target interface was confirmed, the operator transitioned from broad probing to attempted exploitation, routing interactive communication sessions back through the obfuscated Fast Labyrinth proxy mesh to move laterally, maintain persistent backchannels or harvest proprietary data from the very same machines their scouts flagged.

The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations. By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state- actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale. Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat.

To secure enterprise boundaries against this type of highly obfuscated tradecraft, Black Lotus Labs recommends the following:

Domain qtproxy.xyz Fast Labyrinth admin plane Primary administrative domain for proxy orchestration

Subdomain Fast Labyrinth admin plane Mapped to IP 1.32.216[.]171 - main target for Go-http-client logins

Domain qt-proxy.org Fast Labyrinth core Active infrastructure element deployed to replace legacy qt-team.com assets

Subdomain jump.qt-proxy.org Fast Labyrinth core Mapped to IP 8.148.149[.]147 - active operational jump box

Domain instantmessagehub.tech Fast Labyrinth core Mapped to IP 47.76.131[.]175 - highly probable administrative interface endpoint

Subdomain mq-task-qt-team.com QScan broker Mapped to IP 154.64.238[.]222 - central RabbitMQ task engine

Subdomain mq-result-qt-team.com QScan backend Mapped to IP 154.64.238[.]247 - central Redis results database server

Network defenders evaluating historical netflow logs or DNS query files should audit for anomalous outbound or bidirectional traffic loops reaching out to the following subdomains on the root domain yotocloud.com, which represent the underlying commercial fastlink.ws transit nodes co-opted by the quartermaster:

Review these current IOCs and visit our GitHub page , which we update continuously.

For broader threat protection and insights, explore these resources:

Analysis of this Infrastructure Quartermaster was performed by Damon Rouse and Steve Rudd, with technical editing by Ryan English and Mike Horka.

Stay ahead of evolving nation-state threats with intelligence from the researchers tracking them in real time. Explore Black Lotus Labs for the latest threat research, technical analysis and insights to help strengthen enterprise defense.