QuickFox Windows supply-chain targeting campaign
Campaign
Summary
Hide ▲
Show ▼
An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. The activity has been present since at least August 2025 and used endpoint checks before implant deployment. The installer pulled JavaScript loaders from cdns3.51quickfox[.]cn, a lookalike for 51quickfox[.]com, then staged a ZIP payload through DLL side-loading. QuickFox removed the malicious components in version 3.59.6, but the campaign shows how a trusted VPN installer can be repurposed for targeted access.
Related Happenings
QuickFox trojanized installer delivered FDMTP backdoor
Malware Activity
H score31
First: 05.08.2026 08:47
Last: 05.08.2026 08:47
Sources 1
How related:
According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.
About this happening:
A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Win...
QuickFox trojanized installer delivered FDMTP backdoor
Malware ActivityHow related: According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.
About this happening: A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Win...
QuickFox hit by network compromise
Incident
H score15
First: 05.08.2026 08:47
Last: 05.08.2026 08:47
Sources 1
How related:
Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.
About this happening:
The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...
QuickFox hit by network compromise
IncidentHow related: Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.
About this happening: The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...
BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse
Malware Activity
H score39
First: 20.01.2026 20:41
Last: 20.01.2026 20:41
Sources 1
About this happening:
North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...
BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse
Malware ActivityAbout this happening: North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...
Latest development: 22.04.2026 17:48
North Korean actor Void Dokkaebi, aka Famous Chollima, is turning the Contagious Interview fake-job lure into a self-propagating software supply-chain infection that abuses compromised developer repositories, malicious VS Code tasks, and injected code to spread malware and steal credentials. The campaign targets developers seeking work, can hide a poisoned .vscode folder in committed code, and Trend Micro said it found more than 750 infected code repositories, more than 500 malicious VS Code task configurations, and 101 commit-tampering instances in March.
Timeline
-
05.08.2026 08:47 2 articles · 2h ago
Fortinet discloses QuickFox supply-chain campaign delivering FDMTP to Windows users
Initial DisclosureFortinet FortiGuard Labs discloses a long-standing supply-chain campaign against QuickFox, a VPN and network acceleration tool for overseas Chinese users, in which a trojanized Windows installer has delivered FDMTP since at least August 2025. The malicious code used a modified Electron renderer HTML file and staged JavaScript payloads from cdns3.51quickfox[.]cn, while QuickFox removed the malicious components in version 3.59.6 after responsible disclosure; Fortinet noted tactical overlap with Mustang Panda and said the campaign appears to have focused on Windows users.
Show sources
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — thehackernews.com — 05.08.2026 08:47
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — thehackernews.com — 05.08.2026 08:47