How China industrialized the infrastructure behind state hacking | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The quartermaster model of hacking

For a year prior to the takedown, Lumen’s Black Lotus Labs tracked QTFY as it functioned as a “quartermaster,” integrating reconnaissance, proxy orchestration, and operational routing into “a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.”

“We were able to see the direct targeting of certain things,” Damon Rouse, senior lead information security engineer at Black Lotus Labs, tells CSO. “And then from that, we were able to find their scanning framework, their application called QScan. And then we were starting to really do some correlation between QScan activity and then follow-on activity from the proxy network called Fast Labyrinth.”

Rouse likened Nanjing Xinjiuwei’s role to that of a defense contractor. “There’s a ton of these companies in China that are usually started directly after people leave the PLA,” he says. “Because of their connections to the PLA, they have a specialized status to do certain things for the PRC government. And it gives the government plausible deniability because it’s not actually coming from their units.”



Click Here For The Original Source.

——————————————————–

..........

.

.