← All stories
● Covered by 1 source · 1 reportHigh impact1 neutral

FBI disrupts proxy network used for Chinese cyber espionage against US critical infrastructure

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • FBI disrupted infrastructure supporting Chinese cyber espionage.
  • Network provided reconnaissance and proxy services for attacks.
  • Targets included U.S. military, government, and critical infrastructure.
  • Black Lotus Labs tracked and helped disrupt the network.

FBI Disrupts Espionage Infrastructure

The FBI has successfully disrupted a technical infrastructure that served as a "quartermaster" for Chinese cyber espionage activities. This infrastructure provided essential services such as reconnaissance, proxy management, and operational routing, enabling covert operations against U.S. targets. The disruption aims to hinder ongoing espionage efforts.

Components of the Espionage Framework

Black Lotus Labs, Lumen Technologies' threat research division, tracked this infrastructure for a year, identifying its key components. These include QScan for target profiling, Fast Labyrinth as an encrypted relay network, QTRouter for physical device access to the proxy infrastructure, and QTProxy for managing relays and custom routes. These elements collectively formed a reusable service for espionage.

Targeted Organizations and Data Theft

The infrastructure was used to profile and steal data from a wide range of U.S. entities. These included military and defense organizations, government networks, universities, research institutions, aerospace and bioinformatics organizations, healthcare providers, financial firms, critical infrastructure and energy companies, and enterprise software vendors. The scope of targets indicates a broad and strategic espionage campaign.

Role of Operational Relay Box Networks

Lumen Technologies noted that the "quartermaster" industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators. ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, and VPS servers, used to relay malicious traffic and obscure its origin. Chinese threat actors have increased their use of ORBs in cyber operations since 2024.

Disruption Efforts and Impact

Black Lotus Labs shared threat intelligence with U.S. government agencies to warn of risks to strategic assets. The researchers disrupted the infrastructure by null-routing traffic to known points used by the quartermaster operators. This action aims to neutralize the network's ability to facilitate further espionage activities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The FBI has disrupted a proxy network infrastructure that facilitated Chinese cyber espionage operations targeting U.S. critical infrastructure. This infrastructure, tracked by Black Lotus Labs, provided reconnaissance, proxy management, and operational routing capabilities for data theft from various U.S. organizations. The disruption impacts China-linked espionage actors who have increasingly used such networks since 2024.