The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.
Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking the infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure.
According to the researchers, the provider offers a reusable service consisting of four distinct operational elements:
QScan : a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating-system fingerprints, and configuration data
: a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating-system fingerprints, and configuration data Fast Labyrinth : an encrypted relay network that conceals communications to and from victim organizations
: an encrypted relay network that conceals communications to and from victim organizations QTRouter : provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system
: provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system QTProxy: a management tool that lets users select relays and configure custom routes through Fast Labyrinth
Overview of the quartermaster infrastructure
Source: Lumen
The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors.
... continue reading