Security1 distinct publisher2 min readPublished
Black Lotus Labs spent a year mapping a service layer that hands reconnaissance, encrypted relays and routing to several Chinese state operators at the same time. IP-overlap attribution assumes that cannot happen.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The sequence in Lumen's telemetry carries more weight than the component names. Networks that QScan discovered or profiled turn up later in bidirectional traffic through Fast Labyrinth [4]. That makes targeting telemetry a deliverable: scan output tells a customer which routes to a target respond, and the relay layer then carries the session. QTProxy sits on top of the Fast Labyrinth nodes and lets an operator take a preconfigured relay or build a path tailored to one target entity [7].
QTRouter is the odd piece. It is a preconfigured physical access device that gates operator and customer access to the proxy infrastructure and to the node management system [6]. Hardware has to be built and delivered, which implies a customer list and a provisioning trail that live outside network telemetry [17]. That is a different seam than an IP block, and a slower one to rotate.
Lumen puts this case in a line with KV-botnet and Raptor Train, citing them as campaigns where APT operators leaned on shared, externally managed infrastructure instead of building obfuscation networks themselves [12]. Those two prior cases and this provider form a pattern documented inside one vendor's research line [14]. Read that way, the quartermaster is a data point in a supply model, not a one-off vendor.
What is firm and what is hedged should be kept apart. The four components, the scanning telemetry and the null routing of known quartermaster infrastructure points are Lumen's own observations [10]. The origin is qualified: the report says the entity may originate from Nanjing, China, and describes it as a private technical quartermaster whose infrastructure has been used by various Chinese threat actors [8]. No downstream group is named as a customer in the published material. Black Lotus Labs says it warned US government agencies and commends FBI and Department of Justice work against Chinese activity targeting US critical infrastructure [11], which is a commendation of broader effort rather than an announced action against this provider.
There is no CVE here and nothing to patch; the defensive steps the report describes are null routing and intelligence sharing [18]. So the value is in hunt logic rather than a remediation queue. Lumen's own argument is that a shared obfuscation network is an operational chokepoint, and that removing one degrades several active campaigns at the same time [13]. The durable artifact for a defender is the pairing that argument rests on: a network profiled by a scanner, then bidirectional traffic reaching it through commercial consumer proxy space [4][5].
Ranked by verification strength, evidence, and original report placement.
For the past year, Lumen's Black Lotus Labs tracked a key infrastructure provider supporting Chinese cyber espionage activities.
Lumen describes the provider as functioning as a "quartermaster" whose operations integrate reconnaissance, proxy orchestration and operational routing into a reusable service layer, letting malicious actors validate access routes and mask activity using shared infrastructure.
Lumen says the quartermaster model depends on four connected components, named QScan, Fast Labyrinth, QTRouter and QTProxy, which together streamline target discovery, communication routing and operational access.
QScan conducts reconnaissance to identify and profile high-value targets, and networks discovered or profiled by QScan later appear in bidirectional communications through Fast Labyrinth.
Fast Labyrinth co-opts commercial proxy infrastructure into an encrypted relay network that obfuscates traffic to and from target entities, and is made up of commercial consumer proxy architectures ("Airport") plus the QTRouter.
QTRouter is a preconfigured physical access device that manages operator and customer access to the proxy infrastructure and to the proxy node management system.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
product
DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's telemetry, nobody's second look
The company that owns the telemetry also names the components, performs the null routing and publishes the account. Lumen shows real work at the architecture level — QScan profiling networks that later surface in Fast Labyrinth's bidirectional traffic, an admin control plane reached through a shipped QTRouter — but what is published carries no indicator list, no node counts and no victim tally, the Nanjing origin arrives hedged as 'may', and the report we have breaks off mid-sentence on the purchasing mechanism. Specific, plausible, and entirely unchecked.
Uptake asserted, never counted
Strip out the assertions and what remains is thin. Lumen says various Chinese actors use the service and points to KV-botnet and Raptor Train as earlier cases of rented obfuscation, but names no customer, counts no relays and quantifies no targets. The only concrete deployments in the story are Lumen's own — null routes on its backbone and a briefing to U.S. agencies — which measure the vendor's response, not the broker's market.
Chokepoint promised, effect unmeasured
The report's boldest sentence is also its emptiest: dismantle one quartermaster and several campaigns degrade at once — asserted, with no before-and-after on the infrastructure Lumen says it null routed weeks or months ago. The same passage stays quiet about what its advice costs, since the relays are commercial subscription proxies with paying customers on them. Offsetting that, the architectural reporting is careful and hedged where it should be, so this reads as a vendor overselling the conclusion rather than the finding.
The only witness also sells the remedy
A backbone carrier with a security practice discovers the threat, names it, blocks it on its own network, tells the government, and commends the FBI and DOJ — all in one post on its own site. Each element is ordinary in vendor research; together they mean the framing, the evidence and the countermeasure trace to a single commercially interested party, and this coverage contains no second publisher to price any of it differently.
Trust the plumbing, not the conclusions
We would stand behind the component descriptions — too internally consistent to be casual — and much less behind Nanjing or the claimed disruption effect. With one publisher, a truncated text and no corroboration, this read should move fast in either direction the moment another team with proxy-network visibility either finds Fast Labyrinth or looks and does not.