Find notable cyber news and cases, enriched with sources, timelines, and signals.

QuickFox trojanized installer delivered FDMTP backdoor

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Windows users and expand access with follow-on tooling. The malicious installer fingerprints the endpoint, checks for reinfection, and only installs the implant on a valid target. The staged payloads are hosted on cdns3.51quickfox[.]cn, which masquerades as the official 51quickfox[.]com domain.

Related Happenings

QuickFox hit by network compromise

Incident
H score15 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.

About this happening: The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...

QuickFox Windows supply-chain targeting campaign

Campaign
H score42 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: Evidence indicates that the campaign solely targeted Windows users.

About this happening: An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. Th...

LOTUSLITE evolved backdoor activity in India banking-sector targeting

Malware Activity
H score23 First: 22.04.2026 10:58 Last: 22.04.2026 10:58 Sources 1

About this happening: An evolved LOTUSLITE backdoor is now being deployed with remote shell, file operations, session management, and data exfiltration capabilities, extending an ...

Timeline

  1. 05.08.2026 08:47 2 articles · 2h ago

    Researchers disclose trojanized QuickFox Windows installer delivering FDMTP backdoor

    Initial Disclosure

    Fortinet FortiGuard Labs disclosed a long-running supply chain attack against QuickFox, a VPN and network acceleration tool for overseas Chinese users, in which a trojanized Windows installer delivered FDMTP through a modified Electron renderer HTML file and JavaScript loader. The malicious code staged payloads from cdns3.51quickfox[.]cn while masquerading as 51quickfox[.]com, fingerprinted endpoints, checked for reinfection, and only installed the implant on Windows systems that matched the operators' filters. QuickFox removed the malicious components in version 3.59.6, with 3.0.51.0 identified as the earliest affected version, and Fortinet noted tactical overlap with Mustang Panda without making a definitive attribution.

    Show sources