← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • QuickFox VPN Windows installer was trojanized to deliver FDMTP backdoor.
  • Attack attributed to Chinese state-sponsored group Mustang Panda.
  • Malicious code was active since at least August 2025.
  • QuickFox removed malicious components in version 3.59.6.

Supply Chain Attack on QuickFox VPN

Cybersecurity researchers have identified a supply chain attack affecting QuickFox, a VPN and network acceleration tool primarily used by overseas Chinese users. The attack involved distributing a trojanized version of the application's Windows installer, which has been active since at least August 2025.

FDMTP Backdoor and Mustang Panda

The trojanized installer delivered FDMTP, a backdoor linked to Mustang Panda, a Chinese state-sponsored threat actor. The attack specifically targeted Windows users, with the earliest affected version identified as 3.0.51.0.

Infection Mechanism

The attack utilized a modified Electron renderer HTML file to download and execute a JavaScript-based loader. This loader fingerprinted the victim's endpoint to confirm it was a valid target before installing the FDMTP implant. The malicious JavaScript code mimicked Google Firebase SDK components and was hosted on a domain designed to resemble the official QuickFox domain to evade detection.

Targeting and Evasion

The malicious payload checked for the presence of specific processes, including Steam, and would abort execution if found. It also checked for 26 domestic applications, cryptocurrency wallets, developer tools, and enterprise software, indicating a targeted approach. This behavior suggests an attempt to avoid detection on systems not matching the attacker's intended profile.

Remediation

Following responsible disclosure, QuickFox removed the malicious components from their Windows installer. The fix was included in version 3.59.6, with changes implemented between July 25 and August 13, 2025.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have uncovered a supply chain attack targeting QuickFox, a VPN service, that has been ongoing since at least August 2025. The attack involved a modified Windows installer delivering the FDMTP backdoor, attributed to the Chinese state-sponsored threat actor Mustang Panda. This incident highlights the ongoing risk of supply chain compromises, particularly for software used by specific user demographics.