Fortinet Identifies Long-Standing Supply Chain Attack on QuickFox Targeting Chinese Users
Fortinet FortiGuard Labs has disclosed a persistent supply chain attack on QuickFox, a VPN and network acceleration tool primarily used by overseas Chinese users. The attack, ongoing since at least August 2025, involves a trojanized version of the application delivering a backdoor known as FDMTP. This backdoor is linked to Mustang Panda, a Chinese state-sponsored threat actor. The attack is executed through a modified Electron renderer HTML file that downloads and executes a JavaScript-based loader. This loader fingerprints the victim's endpoint to determine if it is a valid target before installing the FDMTP implant. QuickFox has since removed the malicious components from their installer. The campaign appears to target Windows users, with the malware checking for specific processes and aborting if certain applications are detected.