QuickFox Supply Chain Attack Delivers FDMTP Backdoor Through Trojanized Windows Installer

Key Topics in this News Article:
News Snapshot:

Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda. “The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader,” the FortiGuard Incident Response Team…

  • This field is for validation purposes and should be left unchanged.
  • Newsletter to Your Inbox

    China intelligence delivered each week!

  • This field is hidden when viewing the form