Find notable cyber news and cases, enriched with sources, timelines, and signals.

QuickFox Windows supply-chain targeting campaign

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing QuickFox supply-chain campaign delivered FDMTP through a trojanized Windows installer, creating a selective backdoor-delivery path for Windows users. The activity has been present since at least August 2025 and used endpoint checks before implant deployment. The installer pulled JavaScript loaders from cdns3.51quickfox[.]cn, a lookalike for 51quickfox[.]com, then staged a ZIP payload through DLL side-loading. QuickFox removed the malicious components in version 3.59.6, but the campaign shows how a trusted VPN installer can be repurposed for targeted access.

Related Happenings

QuickFox trojanized installer delivered FDMTP backdoor

Malware Activity
H score31 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.

About this happening: A trojanized QuickFox Windows installer has been used to deliver the FDMTP backdoor, extending a long-running supply-chain compromise that can selectively infect Win...

QuickFox hit by network compromise

Incident
H score15 First: 05.08.2026 08:47 Last: 05.08.2026 08:47 Sources 1

How related: Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6.

About this happening: The QuickFox Windows installer was compromised with malicious components, putting Windows users at risk of a supply-chain backdoor delivery. QuickFox removed the m...

BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse

Malware Activity
H score39 First: 20.01.2026 20:41 Last: 20.01.2026 20:41 Sources 1

About this happening: North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...

Latest development: 22.04.2026 17:48

North Korean actor Void Dokkaebi, aka Famous Chollima, is turning the Contagious Interview fake-job lure into a self-propagating software supply-chain infection that abuses compromised developer repositories, malicious VS Code tasks, and injected code to spread malware and steal credentials. The campaign targets developers seeking work, can hide a poisoned .vscode folder in committed code, and Trend Micro said it found more than 750 infected code repositories, more than 500 malicious VS Code task configurations, and 101 commit-tampering instances in March.

Timeline

  1. 05.08.2026 08:47 2 articles · 2h ago

    Fortinet discloses QuickFox supply-chain campaign delivering FDMTP to Windows users

    Initial Disclosure

    Fortinet FortiGuard Labs discloses a long-standing supply-chain campaign against QuickFox, a VPN and network acceleration tool for overseas Chinese users, in which a trojanized Windows installer has delivered FDMTP since at least August 2025. The malicious code used a modified Electron renderer HTML file and staged JavaScript payloads from cdns3.51quickfox[.]cn, while QuickFox removed the malicious components in version 3.59.6 after responsible disclosure; Fortinet noted tactical overlap with Mustang Panda and said the campaign appears to have focused on Windows users.

    Show sources