Find notable cyber news and cases, enriched with sources, timelines, and signals.

QuickFox hit by network compromise

Incident
First reported
Last updated
Happening score
H score 15
1 unique sources, 1 articles

Summary

Hide ▲

The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the malicious code in version 3.59.6 after responsible disclosure, and the earliest affected build was 3.0.51.0. The installer abuse mattered because it could stage FDMTP on selected endpoints through a trusted distribution path.

Related Happenings

QuickFox trojanized installer delivered FDMTP backdoor

Malware Activity
H score31 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.

About this happening: A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Win...

QuickFox Windows supply-chain targeting campaign

Campaign
H score42 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: Evidence indicates that the campaign solely targeted Windows users.

About this happening: An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. Th...

Timeline

  1. 05.08.2026 08:47 2 articles · 2h ago

    Fortinet discloses QuickFox supply-chain attack delivering FDMTP

    Initial Disclosure

    Fortinet FortiGuard Labs disclosed a long-standing supply-chain attack against QuickFox, a VPN and network acceleration tool for overseas Chinese users, and said the trojanized Windows installer had delivered FDMTP since at least August 2025. The malicious installer used a modified Electron renderer HTML file to download JavaScript payloads from cdns3.51quickfox[.]cn, fingerprint Windows endpoints, and install the backdoor only on selected targets; QuickFox removed the malicious components in version 3.59.6 after responsible disclosure, and Fortinet noted tactical overlaps with Mustang Panda.

    Show sources