hacker-news · Crawled Aug 5, 2026

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

5 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

A long-standing supply chain attack has affected QuickFox, a VPN and network acceleration tool, since at least August 2025. The malicious Windows installer, starting from version 3.0.51.0, delivers a backdoor called FDMTP via a trojanized Electron-based application. The attack uses a JavaScript loader that fingerprints the victim endpoint and downloads the payload from a malicious domain, cdns3.51quickfox[.]cn, which mimics the legitimate domain. The malware employs DLL side-loading to execute FDMTP, which communicates with a C2 server to exfiltrate system information and download additional plugins, targeting users such as Chinese expatriates and professionals interacting with Chinese speakers.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain cdns3[.]51quickfox[.]cn Details →
Filename firebase-app-compat.js Details →
Filename firebase-analytics-compat.js Details →
Filename Client.dll Details →
Filename update.bin Details →

MITRE ATT&CK TTPs 15 techniques