FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
Summary
Hide ▲
Show ▼
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing support tied to operations against U.S. critical infrastructure. The action targeted infrastructure that had supported follow-on access and activity against sectors including military, government, healthcare, financial, energy, and universities. The disruption limits a reusable relay and management service that helped conceal operator identity and route malicious traffic.
Related Happenings
The “quartermaster” alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score31
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
How related:
Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators.
About this happening:
The “quartermaster” has industrialized Operational Relay Box (ORB) networks for China-linked espionage operators, expanding stealthy routing and proxy management at sc...
The “quartermaster” alliance reshapes ransomware ecosystem operations
Threat Actor MetaHow related: Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators.
About this happening: The “quartermaster” has industrialized Operational Relay Box (ORB) networks for China-linked espionage operators, expanding stealthy routing and proxy management at sc...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
Campaign
H score17
First: 19.08.2026 20:50
Last: 19.08.2026 20:50
Sources 1
About this happening:
The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
CampaignAbout this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure
Public Sector Action
H score28
First: 28.07.2026 21:41
Last: 28.07.2026 21:41
Sources 1
About this happening:
CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...
CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure
Public Sector ActionAbout this happening: CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
Campaign
H score36
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
CampaignAbout this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Timeline
-
26.08.2026 17:17 2 articles · 2h ago
FBI disrupts quartermaster infrastructure used for Chinese cyber espionage
Initial DisclosureThe FBI disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing for Chinese cyber espionage activities. Black Lotus Labs, the threat research arm of Lumen Technologies, tracked the infrastructure for the past year and identified QScan, Fast Labyrinth, QTRouter, and QTProxy as components of the framework used against U.S. military, defense, government, university, aerospace, bioinformatics, healthcare, financial, critical infrastructure, energy, and enterprise software targets.
Show sources
- FBI disrupts proxy network enabling Chinese espionage operations — www.bleepingcomputer.com — 26.08.2026 17:17
- FBI disrupts proxy network enabling Chinese espionage operations — www.bleepingcomputer.com — 26.08.2026 17:17