QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Summary

A long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool for overseas Chinese users, has been disclosed by cybersecurity researchers. The attack, ongoing since at least August 2025, involves a trojanized version of the application used to deliver the FDMTP backdoor.

IFF Assessment

FOE

The discovery of a backdoor delivered via a trojanized application represents a significant threat to users and a success for malicious actors.

Defender Context

This incident highlights the persistent risks associated with supply chain attacks, where trusted software can be compromised to distribute malware. Defenders should maintain vigilance on software supply chains, especially for tools used by specific user groups, and ensure robust endpoint detection and response capabilities are in place to identify and neutralize backdoors.

Read Full Story →