QuickFox trojanized installer delivered FDMTP backdoor
Malware Activity
Summary
Hide ▲
Show ▼
A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Windows users and expand access with follow-on tooling. The malicious installer fingerprints the endpoint, checks for reinfection, and only installs the implant on a valid target. The staged payloads are hosted on cdns3.51quickfox[.]cn, which masquerades as the official 51quickfox[.]com domain.
Related Happenings
QuickFox hit by network compromise
Incident
H score15
First: 05.08.2026 08:47
Last: 05.08.2026 08:47
Sources 1
How related:
Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.
About this happening:
The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...
QuickFox hit by network compromise
IncidentHow related: Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.
About this happening: The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...
QuickFox Windows supply-chain targeting campaign
Campaign
H score42
First: 05.08.2026 08:47
Last: 05.08.2026 08:47
Sources 1
How related:
Evidence indicates that the campaign solely targeted Windows users.
About this happening:
An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. Th...
QuickFox Windows supply-chain targeting campaign
CampaignHow related: Evidence indicates that the campaign solely targeted Windows users.
About this happening: An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. Th...
LOTUSLITE evolved backdoor activity in India banking-sector targeting
Malware Activity
H score23
First: 22.04.2026 10:58
Last: 22.04.2026 10:58
Sources 1
About this happening:
An evolved LOTUSLITE backdoor is now being deployed with remote shell, file operations, session management, and data exfiltration capabilities, extending an ...
LOTUSLITE evolved backdoor activity in India banking-sector targeting
Malware ActivityAbout this happening: An evolved LOTUSLITE backdoor is now being deployed with remote shell, file operations, session management, and data exfiltration capabilities, extending an ...
Timeline
-
05.08.2026 08:47 2 articles · 2h ago
Researchers disclose trojanized QuickFox Windows installer delivering FDMTP backdoor
Initial DisclosureFortinet FortiGuard Labs disclosed a long-running supply chain attack against QuickFox, a VPN and network acceleration tool for overseas Chinese users, in which a trojanized Windows installer delivered FDMTP through a modified Electron renderer HTML file and JavaScript loader. The malicious code staged payloads from cdns3.51quickfox[.]cn while masquerading as 51quickfox[.]com, fingerprinted endpoints, checked for reinfection, and only installed the implant on Windows systems that matched the operators' filters. QuickFox removed the malicious components in version 3.59.6, with 3.0.51.0 identified as the earliest affected version, and Fortinet noted tactical overlap with Mustang Panda without making a definitive attribution.
Show sources
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — thehackernews.com — 05.08.2026 08:47
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — thehackernews.com — 05.08.2026 08:47