The “quartermaster” alliance reshapes ransomware ecosystem operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
The “quartermaster” has industrialized Operational Relay Box (ORB) networks for China-linked espionage operators, expanding stealthy routing and proxy management at scale. The model replaces bespoke compromise chains with reusable relay infrastructure, making source attribution harder and operational tempo faster. It also increases reach into U.S. critical infrastructure by hiding traffic behind rotating commercial proxy nodes.
Related Happenings
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
How related:
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementHow related: The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.
About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
Campaign
H score36
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
CampaignAbout this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
China-nexus threat-Flax Typhoon-Volt Typhoon alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score33
First: 23.04.2026 23:52
Last: 23.04.2026 23:52
Sources 1
About this happening:
China-nexus threat actors are industrializing covert botnet infrastructure, expanding deniable reconnaissance, malware delivery, and data exfiltration against US...
China-nexus threat-Flax Typhoon-Volt Typhoon alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: China-nexus threat actors are industrializing covert botnet infrastructure, expanding deniable reconnaissance, malware delivery, and data exfiltration against US...
Timeline
-
26.08.2026 17:17 2 articles · 2h ago
FBI disrupts quartermaster infrastructure used for Chinese cyber espionage
Initial DisclosureThe FBI disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing for Chinese cyber espionage. Black Lotus Labs said it had tracked the framework for the past year and identified QScan, Fast Labyrinth, QTRouter, and QTProxy as reusable components used against U.S. critical infrastructure and other high-value organizations. The researchers also said they null-routed traffic to known infrastructure points and assessed that the quartermaster industrialized ORB networks by purchasing premium access to selected fastlink.ws nodes.
Show sources
- FBI disrupts proxy network enabling Chinese espionage operations — www.bleepingcomputer.com — 26.08.2026 17:17
- FBI disrupts proxy network enabling Chinese espionage operations — www.bleepingcomputer.com — 26.08.2026 17:17