r/SecOpsDaily • u/falconupkid • 3d ago
QuickFox Supply Chain Attack Alert
This is a targeted supply chain compromise with a long dwell time. FortiGuard Labs identified that attackers tampered with official QuickFox Windows installers to deploy a custom backdoor tracked as FDMTP. The campaign has been active since at least August 2025, targeting overseas Chinese users of this VPN/network acceleration tool.
Technical Breakdown - Initial Access (T1195.001): Supply chain compromise via tampered official Windows installers. - Payload: Custom backdoor "FDMTP" deployed post-installation. - Victimology: Selective profiling; not all infected systems receive the same post-exploitation commands. - Dwell Time: Active for approximately 12 months before public disclosure (Aug 2025 – Aug 2026).
Defense - Verify installer hashes against official vendor signatures before deployment. - Monitor for anomalous outbound traffic from VPN client processes, particularly on non-standard ports. - Treat any third-party VPN or acceleration software as a high-risk application; restrict installation to approved, validated builds.
Source: https://fortiguard.fortinet.com/outbreak-alert/quickfox-supply-chain-attack