Compromised QuickFox Installers: FDMTP Backdoor Targets Windows Users
FortiGuard Labs identifies supply chain attack in QuickFox VPN installers, delivering FDMTP backdoor to Windows users since August 2025. Mitigation steps provided.
Illustrative image generated with AI
Supply Chain Attack
FortiGuard Labs identified a supply chain compromise affecting QuickFox, a VPN and network acceleration tool used by Chinese users abroad.
Windows installers from version 3.0.51.0 onward deliver the FDMTP backdoor through a JavaScript loader and side-loaded DLL components. The campaign has been active since at least August 2025.
The tampering was likely introduced between July 25 and August 13, 2025. QuickFox removed the malicious components in version 3.59.6.
The code uses naming conventions and a structure associated with the Google Firebase SDK. Specifically, the loader uses firebase-app-compat.js, hosted on cdns3.51quickfox[.]cn, a domain resembling the legitimate 51quickfox[.]com.
Fingerprinting Before Payload Delivery
The installer does not automatically download the malware on every machine. The loader gathers system information, checks running processes, and determines whether the endpoint matches the operator’s criteria.
Only systems deemed valuable receive a ZIP archive containing the next-stage infection components. The targeting appears to focus on Chinese users outside China and professionals who interact with Chinese-speaking individuals, although the campaign’s objective has not been confirmed.
Fortinet observed two generations of the malware:
- the first, available since at least September 2025, embeds FDMTP in
Client.dll; - the second, observed since May 2026, stores the backdoor in an encrypted
update.binfile.
Possible involvement by Mustang Panda remains a hypothesis rather than a definitive attribution.
FDMTP Backdoor Capabilities
FDMTP can collect system, network, user, antivirus, process, and active-application data. The malware communicates with a command-and-control server and can exfiltrate the collected information.
Available capabilities also include:
- receiving and executing plugins;
- downloading files and executing remote commands;
- creating scheduled tasks;
- maintaining persistence through the Windows Registry.
The threat is particularly serious because the payload is distributed with software that users intentionally install. The attack affects Windows endpoints exclusively.
Checks and Mitigations
Organizations should:
- update QuickFox to version 3.59.6 or later;
- remove previous installers and packages, especially versions 3.0.51.0 and later;
- inspect Windows endpoints where compromised installers were executed;
- search for connections to
cdns3.51quickfox[.]cn; - check for
Client.dll,update.bin, and DLLs loaded through side-loading; - review processes, scheduled tasks, persistence keys, and C2 communications.
Suspicious endpoints should be isolated. Credentials used on those systems should also be rotated after remediation.
Sources
This article is an original reworking based on the sources below.




