How the Chinese Communist Party Industrializes Network Spy Activities: A Comprehensive Analysis

The Chinese Communist Party’s cyber attacks targeting countries worldwide have been widely known, prompting Western countries to take action. Cyber security experts from a well-known American laboratory have discovered a new pattern in Chinese Communist cyber espionage activities, where the attacks are being industrialized. To combat this new mode of cyber attacks, three major measures can be taken.

Over the past year, Black Lotus Labs, a top cyber threat intelligence and research laboratory under Lumen Technology, has been tracking and investigating the critical infrastructure supporting Chinese Communist cyber espionage activities. They found that Chinese hackers are increasingly relying on professional infrastructure rather than building their own tools, obtaining target intelligence, proxy nodes, covert communication methods, network routing, and management systems through specialized infrastructure. This shift makes Chinese cyber attacks faster, more covert, and capable of serving multiple attack operations simultaneously.

According to the research report released by the laboratory, this model operates like a “cyber quartermaster,” providing logistical support to cyber attackers by identifying targets, establishing covert channels, managing proxy servers, and then providing resources to Chinese hackers.

The report details that the “cyber quartermaster” model consists of four components: QScan, Fast Labyrinth, QTRouter, and QTProxy. Each component has a specific role – QScan identifies targets, Fast Labyrinth conceals identities, QTRouter handles access, while QTProxy manages and controls proxy nodes. This combination standardizes cyber attacks, makes them more repeatable, and cleverly conceals identities.

QScan functions like a scout in the cyber world, conducting large-scale scans of the internet to pinpoint high-value targets in government, military, universities, energy, finance, healthcare, and corporate sectors, collecting target network information such as open ports, software used, and system configurations.

Fast Labyrinth primarily focuses on hiding the attackers. It utilizes commercial proxy networks to blend hackers’ network traffic with a large volume of regular user traffic to obfuscate the true source.

QTRouter handles system access, providing pre-configured physical access devices to manage attackers entering the proxy network.

QTProxy is responsible for managing and controlling proxy nodes, selecting pre-configured network routes or adjusting communication pathways based on the target.

The report highlights a case involving an organization possibly from Nanjing that provides specialized cyber attack infrastructure and technical support, which has been used multiple times by Chinese hackers.

The report points out that Chinese Communist cyber attack organizations leverage the “cyber quartermaster” model, abandoning traceable Virtual Private Server (VPS) hosting services and manual construction of thousands of independent Internet of Things devices to establish Operation Relay Base (ORB – a network of relay nodes specifically designed to hide the origin of a network attack). Instead, they opt for premium “airport” network subscriptions.

Here, “airport” refers to commercial network proxy services specifically designed to bypass the Great Firewall (GFW). Subsequently, attackers exploit the features of commercial networks to quickly gain high-speed and stable international network connections, blending attack traffic with normal user traffic.

These commercial proxy nodes constantly change IP addresses, mixing attack traffic with normal traffic to evade traditional defense mechanisms like IP blacklists and geographical IP access restrictions. This means that solely relying on IP blocking, as in the past, may not fully resolve the issue if attackers use normal commercial proxy services and constantly switch nodes.

Based on Black Lotus Labs’ tracking of network traffic, these networks are not merely scanning the internet haphazardly but are precisely targeting key institutions with strategic value, especially in the United States’ military and defense networks, defense suppliers, governmental agencies, university research institutions, aerospace, satellites, advanced physics, bioinformatics, energy, finance, and critical infrastructure sectors.

Universities and research institutions of global prominence are particularly noteworthy, as they hold a wealth of research findings and may open certain network resources for international cooperation and academic exchanges, making them prime targets for Chinese hackers to map out.

The report reveals that the network scans focus on advanced physics, aerospace, satellite systems, and bioinformatics research fields, seeking out exposed development environments, unpatched cloud storage, and potentially compromised accounts on the internet.

Regarding US military, intelligence, and federal government networks, attackers adopt more cautious approaches, conducting large-scale, long-term network scans. While these scans are often intercepted by US network defense systems, they may not directly obtain a significant amount of information.

Nevertheless, through persistent scanning, attackers gradually gain insight into the external boundaries of target networks, such as available interfaces, open services, and changes in network configurations. This approach allows them to continuously update a long-term “network map” of their targets.

For enterprises and research institutions with weaker defense capabilities or possessing special value, attackers employ more precise scanning methods, focusing on remote management interfaces, system versions, and network trust boundaries.

The report indicates a notable overlap in targets discovered by QScan and Fast Labyrinth. After QScan identifies and scans some targets, the Fast Labyrinth proxy network subsequently communicates with these targets.

The investigation shows that on some high-value strategic targets, where initially there was only one-way, rudimentary reconnaissance, stable bi-directional, high-bandwidth communication channels emerge over time.

The report suggests that this transition from mere “reconnaissance” to active “exploitation” indicates that attackers may proceed to lateral movement, establish long-term backdoor communications, or access proprietary data in target systems.

The most concerning aspect of this model, as highlighted in the report, is that the infrastructure can be shared among multiple attackers. Shared infrastructure has become a crucial strategic node in Chinese Communist cyber espionage operations, which have become highly industrialized.

In the past, if one hacker group was discovered, it meant one exposed attack operation. However, with multiple attackers relying on the same “quartermaster,” a single infrastructure provider may support numerous cyber espionage activities simultaneously. The report also warns that for defenders, discovering and dismantling this “logistical center” could simultaneously weaken multiple attack operations.

The report cautions that looking ahead, the concern lies in the continuous expansion of this “cyber quartermaster” model; Chinese Communist cyber espionage, previously characterized by decentralized small-scale hacking, could further evolve into an industrialized attack system that is scalable, shareable, and rapidly deployable.

In conclusion, the report recommends three major measures to counter such cyber attacks. Firstly, strengthen defenses by adhering to standards set by the US Cybersecurity and Infrastructure Security Agency (CISA), and the UK National Cyber Security Centre (NCSC) to guard against government-level cyber attacks such as those from the Chinese Communist Party. Secondly, utilize Secure Access Service Edge (SASE) services to reduce network exposure points. Lastly, promptly update devices by patching routers, firewalls, and IoT devices to prevent exploitation by hackers.