Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
QuickFox VPN Targeted in Supply Chain Attack Exposing Users

QuickFox VPN Targeted in Supply Chain Attack Exposing Users

Posted on August 5, 2026 By CWS

Cybersecurity experts have revealed a persistent supply chain attack targeting QuickFox, a VPN service popular among overseas Chinese users. This attack, which has been active since at least August 2025, involves a compromised version of the application distributing the FDMTP backdoor, attributed to the Chinese state-aligned group known as Mustang Panda.

Attack Methodology and Execution

The attack exploits a modified Electron renderer HTML file to deliver a JavaScript-based loader. This loader conducts an initial assessment of the victim’s system to determine its suitability before deploying the FDMTP implant. Researchers from Fortinet FortiGuard Labs have identified that the malware specifically targets Windows users.

Upon disclosure, QuickFox took action by releasing an updated version 3.59.6 of their software, removing the harmful components. The attack traces back to version 3.0.51.0, with the malicious code comprising two JavaScript payloads masked as legitimate files on the domain “cdns3.51quickfox[.]cn.”

Technical Details of the Malware

The malware, designed to evade detection, uses one legitimate Google Firebase code and another obfuscated payload mimicking Firebase SDK. The script checks for specific processes to avoid executing on systems with applications like Steam or various domestic apps, cryptocurrency wallets, and developer tools.

Once the conditions are satisfied, it downloads a ZIP payload, utilizing DLL side-loading to activate the FDMTP backdoor. Two generations of this payload have been identified, differing in their method of deploying the backdoor.

Implications and Future Outlook

The FDMTP backdoor, first noted by Trend Micro in 2024, gathers extensive system information, including antivirus status and network details, and communicates with a command-and-control server. The threat actor can further load plugins to expand its capabilities, such as managing scheduled tasks and maintaining registry persistence.

While specific attribution remains uncertain, the tactical approach aligns with Mustang Panda’s known methods. The campaign’s focus on QuickFox’s user base suggests potential targeting of Chinese citizens abroad or professionals engaged with Chinese speakers. The overall impact of this campaign underscores the importance of vigilance in software supply chain security.

As the cybersecurity landscape evolves, organizations and individuals must stay informed about such threats and take proactive measures to safeguard their digital environments.

The Hacker News Tags:Cybersecurity, DLL side-loading, FDMTP, Malware, Mustang Panda, QuickFox, supply chain attack, threat actor, VPN, Windows

Post navigation

Previous Post: Critical RCE Flaw in Major Code Editors Affects Millions
Next Post: Critical Veeam ONE Flaws Enable Remote Code Execution

Related Posts

Researchers Expose Cyber Scheme Using Fake Installers Researchers Expose Cyber Scheme Using Fake Installers The Hacker News
Rethinking AI Data Security: A Buyer’s Guide  Rethinking AI Data Security: A Buyer’s Guide  The Hacker News
ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability The Hacker News
NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors The Hacker News
Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion The Hacker News
NadMesh Botnet Exploits AI Services for Cloud Credentials NadMesh Botnet Exploits AI Services for Cloud Credentials The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark