Find notable cyber news and cases, enriched with sources, timelines, and signals.

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing support tied to operations against U.S. critical infrastructure. The action targeted infrastructure that had supported follow-on access and activity against sectors including military, government, healthcare, financial, energy, and universities. The disruption limits a reusable relay and management service that helped conceal operator identity and route malicious traffic.

Related Happenings

The “quartermaster” alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score31 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

How related: Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators.

About this happening: The “quartermaster” has industrialized Operational Relay Box (ORB) networks for China-linked espionage operators, expanding stealthy routing and proxy management at sc...

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure

Public Sector Action
H score28 First: 28.07.2026 21:41 Last: 28.07.2026 21:41 Sources 1

About this happening: CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

Calypso telecommunications espionage campaign using Showboat and JFMBackdoor

Campaign
H score36 First: 21.05.2026 17:00 Last: 21.05.2026 17:00 Sources 1

About this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...

Timeline

  1. 26.08.2026 17:17 2 articles · 2h ago

    FBI disrupts quartermaster infrastructure used for Chinese cyber espionage

    Initial Disclosure

    The FBI disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing for Chinese cyber espionage activities. Black Lotus Labs, the threat research arm of Lumen Technologies, tracked the infrastructure for the past year and identified QScan, Fast Labyrinth, QTRouter, and QTProxy as components of the framework used against U.S. military, defense, government, university, aerospace, bioinformatics, healthcare, financial, critical infrastructure, energy, and enterprise software targets.

    Show sources