As cited
Copy frozen at (site build).
threat intel
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Fortinet FortiGuard Labs disclosed a supply chain attack against QuickFox, a VPN and network acceleration tool, ongoing since at least August 2025. The attack delivers FDMTP backdoor malware through trojanized Windows installers of the application.
Why it matters: Organizations and individuals using QuickFox for network connectivity face unauthorized remote access and data exfiltration risk; verify installer integrity and check for FDMTP indicators of compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Fortinet FortiGuard Labs disclosed a supply chain attack against QuickFox, a virtual private network (VPN) and network acceleration tool targeting overseas Chinese users. The attack, active since at least August 2025, distributes trojanized Windows installers that deliver the FDMTP backdoor. The campaign represents an extended compromise of the application's distribution mechanism.
Why it matters: Users of QuickFox and organizations supporting overseas Chinese users face credential theft and persistent system compromise; practitioners should verify application integrity and audit QuickFox installations for the FDMTP backdoor.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Fortinet FortiGuard Labs disclosed a supply chain attack against QuickFox, a virtual private network (VPN) and network acceleration tool targeting overseas Chinese users. The attack, active since at least August 2025, distributes trojanized Windows installers that deliver the FDMTP backdoor. The campaign represents an extended compromise of the application's distribution mechanism.
Why it matters: Users of QuickFox and organizations supporting overseas Chinese users face credential theft and persistent system compromise; practitioners should verify application integrity and audit QuickFox installations for the FDMTP backdoor.
- Source published
- First seen by Cybersecurity Tracker