FBI disrupts proxy network enabling Chinese espionage operations

The FBI has dealt a significant blow to Chinese cyber espionage operations by disrupting a sophisticated proxy network used by threat actors linked to Beijing. The network, known as “quartermaster,” was designed to provide reconnaissance, proxy management, and operational routing capabilities for China’s intelligence agencies.

At the heart of this operation is a group called QTFY/QT/QTCYBER, which has been targeting some of America’s most sensitive networks, including NASA, the Federal Reserve, and several government departments. Court documents reveal that QTFY includes former members of the Chinese People’s Liberation Army military wing, indicating that Beijing’s involvement in these activities is more than just a mere accusation.

The proxy network was made up of two key components: QScan and QTRouter. QScan is a scanning and exploitation platform designed to identify high-value targets by collecting open ports, application banners, operating system fingerprints, and configuration data. Meanwhile, QTRouter provides preconfigured physical devices that handle access to the proxy infrastructure and node management system. These tools were used to profile and steal sensitive information from organizations across various sectors, including defense, finance, healthcare, and research.

To make matters worse, QTFY was selling access to these platforms for other actors to scan and exploit vulnerable IoT devices, which could then be added as botnet nodes to further obfuscate the origin of malicious traffic. This industrialized approach to building Operational Relay Box (ORB) networks has become increasingly popular among Chinese threat actors since 2024.

The disruption of QTFY’s infrastructure is a significant victory for the FBI and its partners, who have been tracking this group’s activities for over a year. The domains associated with the quartermaster operation – qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com – have been seized and now display a law enforcement banner.

The use of ORB networks is particularly concerning because it allows threat actors to blend their malicious traffic with legitimate consumer proxy traffic. This makes it extremely difficult for security teams to detect and block such attacks. As Black Lotus Labs notes, the quartermaster platform has effectively industrialized the creation of these networks, making them more accessible and affordable for Chinese espionage operators.

In light of this incident, organizations should be aware of the growing threat posed by ORB networks and take steps to protect themselves. This includes implementing robust security measures to detect and block suspicious traffic, as well as staying vigilant about potential IoT vulnerabilities that can be exploited by threat actors.


Source: Bleeping Computer — 2026-08-26