Cybersecurity experts have revealed a significant supply chain attack affecting QuickFox, a VPN and network acceleration tool for overseas Chinese users. Fortinet FortiGuard Labs identified that this attack, active since at least August 2025, involves a compromised version of the application, delivering the FDMTP backdoor. This backdoor is linked to Mustang Panda, a known Chinese state-sponsored threat group. The attack is carried out through a modified Electron renderer HTML file, which executes a JavaScript-based loader. This loader checks for valid targets and, if confirmed, downloads and installs the FDMTP implant. QuickFox has since removed the malicious components from their Windows installer in version 3.59.6, with the earliest affected version being 3.0.51.0. The campaign specifically targets Windows users. The installer contained two lines of JavaScript in an HTML file, executing two payloads from a domain mimicking QuickFox's official site. The malicious 'firebase-app-compat.js' payload ascertains if a Windows system is running and interacts with a command-and-control server to prevent re-infection. It also checks for specific processes, halting execution if certain applications like Steam are detected. If conditions are met, it downloads the next stage payload from the same domain. This malware collects detailed system information and allows the threat actor to load additional plugins. Although Fortinet has not directly attributed the attack to a specific actor, similarities with Mustang Panda's methods suggest their involvement. The campaign may have targeted Chinese citizens living abroad or professionals interacting with Chinese speakers, though the exact targets remain unclear.
QuickFox Supply Chain Breach Unveils FDMTP Backdoor Deployment
QuickFox supply-chain compromise trojanized Windows installer to deliver FDMTP backdoor in deployments since at least August 2025.


