← Back to blog

Trojanized QuickFox VPN Installer Delivered FDMTP Backdoor

A supply chain attack targeting QuickFox VPN has been delivering the FDMTP backdoor since August 2025. Security teams should review third-party dependencies and distribution channels.

TL;DR

  • Attackers compromised QuickFox VPN's installer to deliver the FDMTP backdoor.
  • The supply chain attack has been active since at least August 2025.
  • Fortinet FortiGuard Labs discovered the trojanized Windows installer.
  • QuickFox is popular among overseas Chinese users for network acceleration.
  • Organizations using QuickFox should verify software integrity immediately.

Cybersecurity researchers from Fortinet FortiGuard Labs have uncovered a persistent supply chain attack targeting QuickFox, a VPN and network acceleration tool widely used by overseas Chinese users. The attackers have been distributing a trojanized version of the Windows installer since at least August 2025, which deploys the FDMTP backdoor onto victim systems.

This compromise represents a significant risk to organizations relying on QuickFox for secure communications. The attack demonstrates how threat actors continue to exploit software distribution channels to gain initial access to target networks. Security teams should assess their exposure and implement verification measures for third-party software installations.

Attack Details

  • The attack involved a modified Windows installer for QuickFox VPN distributed through official channels
  • FDMTP backdoor was delivered as the primary payload to compromised systems
  • Initial compromise dates back to August 2025, indicating a long-term operation
  • QuickFox serves primarily overseas Chinese users seeking network acceleration services

Security Implications

  • Supply chain attacks like this bypass traditional endpoint defenses by appearing legitimate
  • Organizations should implement software integrity checks and digital signature validation
  • Third-party applications require the same security scrutiny as internally developed software
  • Incident response teams should monitor for FDMTP backdoor indicators of compromise

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Trojanized QuickFox VPN Installer Delivered FDMTP Backdoor — Agent Breach Blog | Agent Breach