FDMTP is a Windows-focused .NET malware family associated with the Chinese state-linked espionage actor Mustang Panda, also tracked as Earth Preta and Twill Typhoon. Initially described as a simple downloader built on the TouchSocket implementation of Duplex Message Transport Protocol (DMTP), it has evolved into a modular backdoor and remote access framework used for secondary control, follow-on payload delivery, host profiling, and long-term access.
FDMTP has been observed in multiple intrusion chains, including delivery by the PUBLOAD downloader and deployment through a supply-chain compromise of the QuickFox VPN and network acceleration software. In the QuickFox case, a trojanized Windows installer used injected JavaScript to fingerprint victims, filter targets, and retrieve later-stage payloads that ultimately installed FDMTP. More recent activity also shows FDMTP delivered through DLL sideloading chains that pair legitimate executables with malicious .NET loaders and encrypted payloads.
Operationally, FDMTP communicates with command-and-control infrastructure over custom TCP using DMTP-based messaging. It performs host reconnaissance and registration, then responds to structured tasking from the server. Reported host profiling includes collection of active window title, installed antivirus products, .NET runtime details, operating system and network information, username, process metadata, and other implant state. The malware can enumerate running processes for additional victim filtering and can retrieve or execute server-supplied components.
Recent variants are heavily obfuscated and generate or decrypt significant portions of their logic at runtime. The framework supports plugin loading, malware updates, and persistence through legitimate-looking Windows and developer-related processes. Documented plugin functionality includes scheduled task management, registry-based persistence, and remote retrieval of files or commands. Observed tradecraft includes DLL sideloading, AppDomain hijacking, in-memory loading of decrypted .NET assemblies, and use of legitimate binaries to blend malicious execution into normal system activity.
FDMTP has been used in cyber espionage operations affecting organizations in the Asia-Pacific region, including government and finance-sector targets. Targeting associated with the QuickFox compromise suggests selective victim filtering and possible interest in users interacting with Chinese-language software ecosystems, developer tooling, enterprise applications, and cryptocurrency-related software. The malware’s progression from downloader to modular access framework reflects Mustang Panda’s broader shift toward adaptable, layered tooling for persistence and post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a backdoor that has been put to use by a Chinese state-sponsored threat actor tracked as Mustang Panda.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Some of the payloads, as detailed by Darktrace earlier this year, facilitate the management of scheduled tasks
allowing the operators to expand its functionality at will. Some of the payloads... facilitate the management of scheduled tasks, oversee Registry persistence, and remotely fetch files or commands.
run the "tasklist" command to obtain a list of currently running processes. This list is then checked for specific process names
the server responds with a "GetInfo" request to gather basic information from the victim's device. The collected data contains the window title of the topmost active program, installed antivirus programs, .NET Framework runtime version, network and operating system information
Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure.
66 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor delivered via a trojanized QuickFox installer. It fingerprints victims, establishes C2 communications, gathers host information, lists running processes, exfiltrates system details, and can load server-supplied plugins for persistence, task management, and remote file/command retrieval.
FDMTP is the malware family explicitly discussed throughout the content. It is delivered via a supply-chain compromise of the QuickFox installer, uses DLL sideloading with legitimate binaries, retrieves encrypted payloads and updated implants from multiple staging domains, and registers to clustered command-and-control infrastructure.
A .NET malware downloader/backdoor used by Mustang Panda that has evolved into a modular remote access framework supporting plugin loading, updates, and persistence via legitimate-looking Windows and developer-related processes.
A .NET malware downloader/backdoor used by Mustang Panda that has evolved into a modular remote access framework supporting plugin loading, updates, persistence, and execution through legitimate-looking Windows and developer-related processes, including DLL sideloading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.