Scworld
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the QuickFox app that was modified to include malicious JavaScript. This JavaScript loader fingerprints the victim's system to identify valid targets before installing the FDMTP backdoor, which can exfiltrate sensitive information. The compromised versions of QuickFox range from 3.51.0 to 3.55.5, with the attack active since at least August 2025. QuickFox has since removed the malicious components in version 3.59.6 and is conducting an internal investigation. The attack primarily targets Chinese users abroad, including students and professionals. The malicious code was delivered via a lookalike domain registered in June 2025, and the infrastructure remains active at the time of reporting.
Key Points: • QuickFox VPN was compromised to deliver a backdoor to Windows users. • The attack is linked to the Chinese state-sponsored group Mustang Panda. • Malicious JavaScript was embedded in the QuickFox app, affecting versions 3.51.0 to 3.55.5.