QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
A "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool intended for Chinese consumers living abroad, has been revealed by cybersecurity researchers.
A Chinese state-sponsored threat actor known as Mustang Panda has been using a trojanized version of the program to distribute FDMTP as a backdoor in the supply chain attack, which has been going on since at least August 2025, according to Fortinet FortiGuard Labs.
According to the FortiGuard Incident Response Team, the attack is carried out through a modified Electron renderer HTML file that downloads and runs a JavaScript-based loader. Before downloading and installing an FDMTP implant, the JavaScript loader first fingerprints the victim endpoint to verify that it is a legitima...

