QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users

QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users

First seen 6 Aug 2026, 07:21 UTC GbhackersScworldUk.Pcmagwww.fortinet.com 76% similarity 75.5

Article Content

Browse articles
ThreatCluster

A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the QuickFox app that was modified to include malicious JavaScript. This JavaScript loader fingerprints the victim's system to identify valid targets before installing the FDMTP backdoor, which can exfiltrate sensitive information. The compromised versions of QuickFox range from 3.51.0 to 3.55.5, with the attack active since at least August 2025. QuickFox has since removed the malicious components in version 3.59.6 and is conducting an internal investigation. The attack primarily targets Chinese users abroad, including students and professionals. The malicious code was delivered via a lookalike domain registered in June 2025, and the infrastructure remains active at the time of reporting.

Key Points: • QuickFox VPN was compromised to deliver a backdoor to Windows users. • The attack is linked to the Chinese state-sponsored group Mustang Panda. • Malicious JavaScript was embedded in the QuickFox app, affecting versions 3.51.0 to 3.55.5.

ThreatCluster AI How this analysis works

Timeline

2025-06-09
Malicious domain registered
The lookalike domain used in the attack was registered, facilitating the malware delivery.
Fortinet
2025-08-01
Supply chain attack began
The QuickFox VPN application was first compromised, leading to the distribution of a trojanized version.
Fortinet
2026-08-06
Fortinet reports on the attack
Fortinet disclosed the ongoing supply chain attack and its implications for QuickFox users.
Fortinet
2026-08-06
QuickFox releases updated version
QuickFox removed the malicious components in version 3.59.6 and initiated an internal investigation.
PCMag

Community

Browse all →