Researchers disclosed a long-running supply-chain compromise of the QuickFox VPN and network acceleration tool in which trojanized Windows installers delivered the FDMTP backdoor. Fortinet said the earliest affected release was 3.0.51.0 and that malicious components remained present until QuickFox removed them in 3.59.6. The attack inserted malicious JavaScript into an Electron renderer file to fingerprint victims, filter targets, and retrieve follow-on payloads from the lookalike domain cdns3[.]51quickfox[.]cn. The infection chain then used DLL side-loading, first through ZIP packages containing legitimate binaries and companion malicious files, and later through a newer variant that loaded an encrypted FDMTP payload.
Fortinet linked the campaign to a broader infrastructure used to register implants, distribute payloads and plugins, and provide cluster information, including domains such as www[.]icloud-cdn[.]net, www[.]google-apis[.]net, www[.]techcheck1[.]com, and several wangmeng-themed hosts. Some delivery URLs served legitimate executables such as vshost.exe or dfsvc.exe as sideloading targets alongside malicious DLLs and configuration files, and the infrastructure showed sustained activity from mid-2025 through mid-2026. Researchers did not make a firm attribution, but said the malware family and tradecraft overlap with activity previously associated with Mustang Panda, suggesting the operation may have targeted Chinese users abroad or people who regularly interact with Chinese speakers.

Trace attribution and downstream blast radius.
12 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs publicly disclosed the long-running QuickFox Windows supply-chain compromise and described it as a targeted espionage-oriented operation using trojanized installers to selectively deploy the FDMTP backdoor. The disclosure stated the campaign had been active since August 2025.
Fortinet reported that some resolving IP activity tied to the infrastructure, including for www[.]wangmeng66[.]top, continued into early July 2026. This extended the observed infrastructure timeline beyond the last-seen date for the primary lookalike domain.
Fortinet said the lookalike domain cdns3[.]51quickfox[.]cn was last observed on this date. The tracked domain activity for the QuickFox supply-chain compromise extended through late June 2026.
Fortinet observed the staging and registration domain www[.]wangmeng66[.]top resolving to numerous non-Cloudflare IP addresses during this period. The behavior indicated rotating infrastructure supporting FDMTP operations.
From May 2026, the attackers shifted to a newer ZIP payload generation. This version used DLL side-loading to launch a .NET loader for an encrypted file named update.bin containing FDMTP.
By at least September 2025, the campaign was distributing its first known ZIP payload generation. This variant used DLL side-loading to launch a malicious Client.dll that embedded FDMTP.
Fortinet reported the QuickFox supply-chain compromise had been ongoing since at least August 2025, using a trojanized Windows installer to deliver the FDMTP backdoor. The malicious installer modified an Electron renderer HTML file to fetch JavaScript payloads from a lookalike domain.
Fortinet observed the lookalike domain cdns3[.]51quickfox[.]cn, used to host initial infection components for the QuickFox supply-chain compromise, beginning on this date. The broader malicious infrastructure activity was tracked from at least this period onward.
Fortinet said the trojanized QuickFox Windows installer contained malicious changes sometime between July 25 and August 13, 2025. It identified QuickFox version 3.0.51.0 as the earliest affected release.
Trend Micro first reported FDMTP as a secondary tool distributed via the PUBLOAD downloader. This establishes prior public awareness of the malware later delivered through the QuickFox supply-chain attack.
Fortinet published research detailing the QuickFox supply-chain compromise, the FDMTP delivery chain, and associated staging and registration infrastructure. The report also noted tradecraft overlaps with activity previously reported by Darktrace.
After responsible disclosure, QuickFox removed the malicious components from its Windows installer in version 3.59.6. This marked the vendor's remediation of the trojanized installer issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 98 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcescworld.com
Open sourcetrojan-killer.net
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourcefeeds.fortinet.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.