Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
QuickFox VPN Targeted in Supply Chain Attack Exposing Users

QuickFox VPN Targeted in Supply Chain Attack Exposing Users

Posted on August 5, 2026 By CWS

Cybersecurity experts have revealed a persistent supply chain attack targeting QuickFox, a VPN service popular among overseas Chinese users. This attack, which has been active since at least August 2025, involves a compromised version of the application distributing the FDMTP backdoor, attributed to the Chinese state-aligned group known as Mustang Panda.

Attack Methodology and Execution

The attack exploits a modified Electron renderer HTML file to deliver a JavaScript-based loader. This loader conducts an initial assessment of the victim’s system to determine its suitability before deploying the FDMTP implant. Researchers from Fortinet FortiGuard Labs have identified that the malware specifically targets Windows users.

Upon disclosure, QuickFox took action by releasing an updated version 3.59.6 of their software, removing the harmful components. The attack traces back to version 3.0.51.0, with the malicious code comprising two JavaScript payloads masked as legitimate files on the domain “cdns3.51quickfox[.]cn.”

Technical Details of the Malware

The malware, designed to evade detection, uses one legitimate Google Firebase code and another obfuscated payload mimicking Firebase SDK. The script checks for specific processes to avoid executing on systems with applications like Steam or various domestic apps, cryptocurrency wallets, and developer tools.

Once the conditions are satisfied, it downloads a ZIP payload, utilizing DLL side-loading to activate the FDMTP backdoor. Two generations of this payload have been identified, differing in their method of deploying the backdoor.

Implications and Future Outlook

The FDMTP backdoor, first noted by Trend Micro in 2024, gathers extensive system information, including antivirus status and network details, and communicates with a command-and-control server. The threat actor can further load plugins to expand its capabilities, such as managing scheduled tasks and maintaining registry persistence.

While specific attribution remains uncertain, the tactical approach aligns with Mustang Panda’s known methods. The campaign’s focus on QuickFox’s user base suggests potential targeting of Chinese citizens abroad or professionals engaged with Chinese speakers. The overall impact of this campaign underscores the importance of vigilance in software supply chain security.

As the cybersecurity landscape evolves, organizations and individuals must stay informed about such threats and take proactive measures to safeguard their digital environments.

The Hacker News Tags:Cybersecurity, DLL side-loading, FDMTP, Malware, Mustang Panda, QuickFox, supply chain attack, threat actor, VPN, Windows

Post navigation

Previous Post: Critical RCE Flaw in Major Code Editors Affects Millions
Next Post: Critical Veeam ONE Flaws Enable Remote Code Execution

Related Posts

Discover Practical AI Tactics for GRC — Join the Free Expert Webinar Discover Practical AI Tactics for GRC — Join the Free Expert Webinar The Hacker News
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack The Hacker News
Optimize SOC Efficiency by Tackling Multi-OS Threats Optimize SOC Efficiency by Tackling Multi-OS Threats The Hacker News
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs The Hacker News
Google Enhances Chrome Security with DBSC Rollout Google Enhances Chrome Security with DBSC Rollout The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States
  • Critical Veeam ONE Flaws Enable Remote Code Execution
  • QuickFox VPN Targeted in Supply Chain Attack Exposing Users
  • Critical RCE Flaw in Major Code Editors Affects Millions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States
  • Critical Veeam ONE Flaws Enable Remote Code Execution
  • QuickFox VPN Targeted in Supply Chain Attack Exposing Users
  • Critical RCE Flaw in Major Code Editors Affects Millions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark