A long-running supply chain attack has been discovered targeting QuickFox, a VPN and network acceleration tool mainly used by Chinese users living outside China. Security researchers from Fortinet found that attackers secretly modified the official Windows installer to spread the FDMTP backdoor. Their investigation shows the campaign has been active since at least August 2025 and specifically targeted Windows systems. The affected installer looked legitimate, making the attack difficult for users to detect.

The attackers inserted only two malicious lines of JavaScript into an HTML file used by QuickFox’s Electron application. When the program was installed, the hidden script quietly downloaded additional JavaScript files from a fake QuickFox-related domain that closely resembled the official website. One file contained genuine Google Firebase code to appear harmless, while the other contained heavily obfuscated malicious code that started the infection process. This allowed the malware to stay hidden during the early stages of execution.
Before installing the final malware, the malicious script carefully checked whether the infected computer matched the attackers’ requirements. It confirmed that the device was running Windows, contacted a command-and-control server, and verified that the system had not already been infected. The malware also collected a list of running processes and stopped execution if Steam was detected. At the same time, it searched for applications such as Visual Studio Code, Git, Navicat, DBeaver, Telegram, cryptocurrency wallets, developer tools, and several Chinese software programs before continuing.

Once these checks were complete, the malware downloaded a ZIP archive containing the next stage of the attack. Researchers identified two different versions of this payload. The first version used DLL side-loading to launch a malicious DLL carrying the FDMTP backdoor, while the newer version loaded an encrypted file named update.bin that contained the same implant. Both versions relied on DLL side-loading techniques to hide malicious activity behind trusted Windows components.
After installation, the FDMTP backdoor contacted its command-and-control server and collected detailed information about the infected computer. It gathered the active window title, installed antivirus software, .NET Framework version, operating system details, network information, username, process ID, installation path, and other system information. This data was sent back to the attackers, allowing them to evaluate whether the infected device was valuable enough for further espionage or follow-up operations.

The malware was also designed to receive additional plugins from its operators, allowing its capabilities to expand whenever needed. Previous research has shown that these plugins can manage scheduled tasks, maintain Registry persistence, and remotely download files or execute commands. This modular design gives attackers the flexibility to customize the malware based on each victim. As a result, compromised systems can remain under long-term control without immediately revealing the full extent of the attack.
Fortinet has not officially attributed the campaign to a specific threat actor, but researchers observed strong technical similarities with Mustang Panda, a Chinese state-sponsored cyber-espionage group known for using DLL side-loading techniques. Because QuickFox is widely used by Chinese international students and expatriates, researchers believe the campaign may have focused on Chinese citizens living abroad. Another possibility is that the attackers targeted professionals who regularly communicate with Chinese organizations for business or diplomatic purposes, although this has not been confirmed.

Following responsible disclosure from Fortinet, QuickFox investigated the issue and removed the malicious components from its Windows installer by releasing version 3.59.6. The company also began an internal investigation into the compromise. Researchers believe the malicious code was introduced sometime between late July and mid-August 2025, with version 3.0.51.0 being the earliest affected release they identified. The incident highlights how trusted software updates can become powerful attack channels and reinforces the importance of verifying software integrity, monitoring supply chains, and responding quickly when compromises are discovered.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news