hacker-news · Crawled Aug 5, 2026
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
5 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
A long-standing supply chain attack has affected QuickFox, a VPN and network acceleration tool, since at least August 2025. The malicious Windows installer, starting from version 3.0.51.0, delivers a backdoor called FDMTP via a trojanized Electron-based application. The attack uses a JavaScript loader that fingerprints the victim endpoint and downloads the payload from a malicious domain, cdns3.51quickfox[.]cn, which mimics the legitimate domain. The malware employs DLL side-loading to execute FDMTP, which communicates with a C2 server to exfiltrate system information and download additional plugins, targeting users such as Chinese expatriates and professionals interacting with Chinese speakers.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 15 techniques
T1021.001 Remote Desktop Protocol · Lateral Movement T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1112 Modify Registry · Defense Evasion T1204.002 Malicious File · Execution T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access