Scworld QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
Article Content
- •QuickFox VPN was compromised to deliver a backdoor to Windows users.
- •The attack is linked to the Chinese state-sponsored group Mustang Panda.
- •Malicious JavaScript was embedded in the QuickFox app, affecting versions 3.51.0 to 3.55.5.
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the QuickFox app that was modified to include malicious JavaScript. This JavaScript loader fingerprints the victim's system to identify valid targets before installing the FDMTP backdoor, which can exfiltrate sensitive information. The compromised versions of QuickFox range from 3.51.0 to 3.55.5, with the attack active since at least August 2025. QuickFox has since removed the malicious components in version 3.59.6 and is conducting an internal investigation. The attack primarily targets Chinese users abroad, including students and professionals. The malicious code was delivered via a lookalike domain registered in June 2025, and the infrastructure remains active at the time of reporting.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Mustang Panda, Fdmtp and QuickFox in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…