FDMTP is a Windows-focused .NET malware family associated with the Chinese state-aligned threat actor Mustang Panda, also tracked as Earth Preta and Twill Typhoon. It was initially described as a simple downloader built on the TouchSocket implementation of the Duplex Message Transport Protocol (DMTP), but later activity shows it evolving into a modular backdoor and remote access framework with plugin support, runtime-obfuscated logic, and flexible post-compromise tasking.
FDMTP has been observed in espionage-oriented intrusion chains rather than broad commodity crime operations. In earlier reporting tied to Earth Preta, it was delivered as a secondary tool by PUBLOAD and embedded in a DLL for DLL sideloading. In later campaigns, it was deployed through a software supply-chain compromise affecting the QuickFox Windows application, where trojanized installers modified Electron components to launch a JavaScript loader that profiled hosts and selectively installed the implant only on systems matching attacker-defined criteria. This selective victim validation indicates targeted operations.
Operationally, FDMTP supports host profiling, command-and-control registration, staged payload retrieval, plugin loading, and persistence. Reported capabilities include collecting system, user, process, antivirus, operating system, .NET runtime, and network information; enumerating running processes; receiving updated components; and executing modular extensions for scheduled task management, Registry-based persistence, and additional remote operations. Multiple investigations also describe its use of DLL sideloading with legitimate Windows or developer-related binaries, encrypted or obfuscated configuration and payload storage, runtime string decryption, and in-memory loading of managed components for defense evasion.
Later variants have been described as a heavily obfuscated DMTP-based backdoor communicating over custom TCP and using cluster-style infrastructure to obtain command nodes and maintain resilient access. The framework has been observed persisting through normal-looking Windows and developer-associated processes, reflecting a shift from a simple downloader toward a more adaptable post-exploitation platform. Targeting linked to FDMTP activity has included government and public-sector entities in the Asia-Pacific region, and the QuickFox supply-chain operation likely exposed overseas Chinese users and related professional communities using the compromised Windows software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
China : Darktrace observed Chinese-nexus actors prioritizing long-term access through trusted services, dynamic-link library (DLL) sideloading, and modular intrusion chains consistent with activity documented in Crimson Echo reporting and associated with Twill Typhoon tradecraft... 'chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor'
21 distinct techniques documented for this family, organized by ATT&CK tactic.
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP
The malware can also manage scheduled tasks and Registry persistence.
Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access.
The group is known for its use of a .NET malware downloader known as FDMTP.
The attack begins with a modified Electron renderer HTML file that downloads and executes a JavaScript loader.
Those lines pulled script files from cdns3[.]51quickfox[.]cn , a domain that resembles QuickFox infrastructure but is not the official 51quickfox[.]com domain.
FDMTP gathers system information, including active programs
FDMTP gathers system information, including active programs, antivirus software, and network details
FDMTP gathers system information, including active programs, antivirus software, and network details
The JavaScript checked that the endpoint was Windows, queried command output such as process listings, and used guardrails before the later stages downloaded and ran the implant.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor associated in the referenced material with Chinese-nexus intrusion tradecraft and long-term access operations.
A custom backdoor delivered via trojanized QuickFox Windows installers in a software supply-chain compromise. It is selectively deployed after system fingerprinting, suggesting a targeted espionage-oriented operation that enables victim profiling and post-compromise access.
A backdoor delivered via a trojanized QuickFox Windows installer. After target validation by a JavaScript loader, it is deployed using DLL side-loading from a ZIP archive. It collects system information such as active programs, antivirus software, and network details, exfiltrates the data to a command-and-control server, and can manage scheduled tasks and Registry persistence.
A backdoor/implant delivered via a trojanized QuickFox Windows installer. The infection chain used modified Electron-loaded HTML and downloaded JavaScript to profile Windows systems, then later loaders sideloaded the implant using csmonitor.exe and a malicious Microsoft.ServiceHosting.Tools.dll. The implant registered the endpoint with staging infrastructure, received cluster nodes, and supported plugin-style modules for remote operations and persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.