Close Menu
NCIJ Network NCIJ Network
    What's Hot

    New XCSSET variant targets macOS devs via compromised Xcode projects

    August 5, 2026

    The crypto project trying to replace the US banking system just pulled its 10 trillion token filing

    August 5, 2026

    Michigan Democratic primary seen as latest test for party’s progressive wing

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New XCSSET variant targets macOS devs via compromised Xcode projects
    • The crypto project trying to replace the US banking system just pulled its 10 trillion token filing
    • Michigan Democratic primary seen as latest test for party’s progressive wing
    • Armed man arrested after appearing to scope out security for Trump fundraising dinner
    • The AI Notetaker Has Been Invited to All the Meetings
    • QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
    • New Ethereum proposal would cut issuance to zero if staked ETH reaches $112 billion
    • NASA Provides Updates on Moon Base Cargo Landers, Tech Demonstrations
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.

    According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.

    “The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader,” the FortiGuard Incident Response Team said. “Upon execution, the JavaScript loader fingerprints the victim endpoint to determine if it’s a valid target before downloading and installing an FDMTP implant.”

    Following responsible disclosure, QuickFox has removed the malicious components from their Windows installer with the release of version 3.59.6. The changes are said to have been included sometime between July 25 and August 13, 2025, with 3.0.51.0 being the earliest affected version. Evidence indicates that the campaign solely targeted Windows users.

    The malicious code introduced to the installer executable involves two lines of JavaScript in a single HTML file, causing it to execute two JavaScript payloads — “firebase-app-compat.js” and “firebase-analytics-compat.js” — staged on “cdns3.51quickfox[.]cn,” which masquerades as the official QuickFox domain (“51quickfox[.]com”) to evade detection.

    Cybersecurity

    Of the two payloads, “firebase-analytics-compat.js” contains legitimate Google Firebase code, while “firebase-app-compat.js” is a heavily obfuscated payload that mimics the Firebase SDK, but harbors functionality to ascertain if the affected endpoint is running Windows, check with a command-and-control (C2) server to ensure the endpoint is not re-infected, and run the “tasklist” command to obtain a list of currently running processes.

    This list is then checked for specific process names, specifically Steam (“steam.exe”), and aborts execution if it is present. It also checks if there exists at least one process name that matches 26 domestic applications, cryptocurrency wallets, developer tools, and enterprise software.

    This includes Xshell, MobaXterm, Tabby Terminal, Navicat, DBeaver, Git, IntelliJ IDEA, Sublime Text, Notepad++, Microsoft Visual Studio Code, Exodus Wallet, Binance, Ledger Live, Trezor Suite, Telegram, SafeW, Ai Fanyi, Haiwang Chuhai, Yi Fanyi, Kuai Fanyi, and HaiYiTong.

    Once both these conditions are met, the script proceeds to download the next stage payload, a ZIP archive from the same aforementioned domain. Two different generations of the ZIP payload have been identified –

    • Generation 1 (Available from at least September 2025), which uses DLL side-loading to launch a malicious DLL embedding FDMTP (“Client.dll”)
    • Generation 2 (Available from May 2026), which also uses DLL side-loading to launch a malicious DLL that acts as a loader for an encrypted file (“update.bin”) that contains FDMTP

    FDMTP was first highlighted by Trend Micro in September 2024 as a secondary tool distributed via a downloader known as PUBLOAD. In the latest iteration, it first attempts to obtain a C2 connection, following which the server responds with a “GetInfo” request to gather basic information from the victim’s device.

    The collected data contains the window title of the topmost active program, installed antivirus programs, .NET Framework runtime version, network and operating system information, current username, and details about the implant itself, such as file full path, version, process ID, and hosting process name.

    Cybersecurity

    Once this information is packaged and exfiltrated, the C2 server sends a request to list running processes in a further attempt to filter out certain endpoints in furtherance of the threat actor’s goals. Additionally, the malware is responsible for loading plugins received from the server, allowing the operators to expand its functionality at will.

    Some of the payloads, as detailed by Darktrace earlier this year, facilitate the management of scheduled tasks, oversee Registry persistence, and remotely fetch files or commands.

    Although Fortinet has not attributed the campaign to a specific threat actor, it acknowledged tactical overlaps with Mustang Panda, a Chinese nation-state adversary known for its reliance on DLL side-loading techniques to deploy malware.

    Given that QuickFox’s primary user base is Chinese international students and expats, it’s suspected that the campaign may have singled out Chinese citizens residing outside China.

    “A competing hypothesis is that this campaign aimed to target professionals required to interact with Chinese native speakers, potentially for trade or diplomatic engagement purposes,” Fortinet said. “Neither hypothesis can be confirmed without understanding the victim context for second-stage intrusions, which would identify true targets of the campaign.”

    attack Backdoor chain Delivers FDMTP Installer QuickFox supply Trojanized Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New XCSSET variant targets macOS devs via compromised Xcode projects

    Zenity Raises $125 Million in Series C Funding

    Murderous heat, an endangered food supply and no net zero: this is the life the radical right wants you to have | George Monbiot

    AI Notetaker Exposes Government, Corporate Video Calls

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    New XCSSET variant targets macOS devs via compromised Xcode projects

    August 5, 2026

    The crypto project trying to replace the US banking system just pulled its 10 trillion token filing

    August 5, 2026

    Michigan Democratic primary seen as latest test for party’s progressive wing

    August 5, 2026

    Armed man arrested after appearing to scope out security for Trump fundraising dinner

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    New XCSSET variant targets macOS devs via compromised Xcode projects

    August 5, 2026

    The crypto project trying to replace the US banking system just pulled its 10 trillion token filing

    August 5, 2026

    Michigan Democratic primary seen as latest test for party’s progressive wing

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.