CyberSecurityBoardThreat Intel · CVEs · Products
Malware

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

August 5, 2026

Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese users. The attack, active since at least August 2025, involved a trojanized Windows installer that delivered the FDMTP backdoor, a malware family previously linked to the Chinese state-sponsored threat actor Mustang Panda.

The malicious code was embedded in a modified Electron renderer HTML file within the installer. It executed two JavaScript payloads staged on a lookalike domain (cdns3.51quickfox[.]cn) that mimics the official QuickFox domain. One payload contained legitimate Google Firebase code, while the other was heavily obfuscated and performed endpoint fingerprinting, checking for Windows, verifying with a C2 server, and running the tasklist command to enumerate processes. The malware aborted if Steam was present and also checked for 26 specific domestic applications, cryptocurrency wallets, developer tools, and enterprise software, including Xshell, MobaXterm, Navicat, DBeaver, Git, IntelliJ IDEA, Sublime Text, Notepad++, VS Code, Exodus Wallet, Binance, Ledger Live, Trezor Suite, and Telegram.

Once conditions were met, the script downloaded a ZIP archive containing the next-stage payload. Two generations of the payload were identified: Generation 1 (since September 2025) used DLL side-loading to launch a malicious DLL embedding FDMTP, while Generation 2 (since May 2026) used DLL side-loading to load an encrypted file (update.bin) containing FDMTP. FDMTP, first highlighted by Trend Micro in September 2024, establishes C2 communication and can gather system information, list processes, and load plugins for expanded functionality, including scheduled task management, Registry persistence, and remote file/command execution.

QuickFox removed the malicious components in version 3.59.6, with the earliest affected version being 3.0.51.0. The campaign targeted Windows users only. While Fortinet did not attribute the attack to a specific actor, tactical overlaps with Mustang Panda were noted. The targeting of QuickFox’s user base—Chinese international students and expats—suggests the campaign may have aimed at Chinese citizens abroad, though a competing hypothesis points to professionals engaging with Chinese speakers for trade or diplomatic purposes.

CVEs: CVE-2026-50522

Attack groups: Mustang Panda

Malware: FDMTP, PUBLOAD

Companies: Fortinet, Trend Micro, Darktrace, QuickFox

Products: QuickFox VPN