Cybersecurity experts have revealed a persistent supply chain attack targeting QuickFox, a VPN service popular among overseas Chinese users. This attack, which has been active since at least August 2025, involves a compromised version of the application distributing the FDMTP backdoor, attributed to the Chinese state-aligned group known as Mustang Panda.
Attack Methodology and Execution
The attack exploits a modified Electron renderer HTML file to deliver a JavaScript-based loader. This loader conducts an initial assessment of the victim’s system to determine its suitability before deploying the FDMTP implant. Researchers from Fortinet FortiGuard Labs have identified that the malware specifically targets Windows users.
Upon disclosure, QuickFox took action by releasing an updated version 3.59.6 of their software, removing the harmful components. The attack traces back to version 3.0.51.0, with the malicious code comprising two JavaScript payloads masked as legitimate files on the domain “cdns3.51quickfox[.]cn.”
Technical Details of the Malware
The malware, designed to evade detection, uses one legitimate Google Firebase code and another obfuscated payload mimicking Firebase SDK. The script checks for specific processes to avoid executing on systems with applications like Steam or various domestic apps, cryptocurrency wallets, and developer tools.
Once the conditions are satisfied, it downloads a ZIP payload, utilizing DLL side-loading to activate the FDMTP backdoor. Two generations of this payload have been identified, differing in their method of deploying the backdoor.
Implications and Future Outlook
The FDMTP backdoor, first noted by Trend Micro in 2024, gathers extensive system information, including antivirus status and network details, and communicates with a command-and-control server. The threat actor can further load plugins to expand its capabilities, such as managing scheduled tasks and maintaining registry persistence.
While specific attribution remains uncertain, the tactical approach aligns with Mustang Panda’s known methods. The campaign’s focus on QuickFox’s user base suggests potential targeting of Chinese citizens abroad or professionals engaged with Chinese speakers. The overall impact of this campaign underscores the importance of vigilance in software supply chain security.
As the cybersecurity landscape evolves, organizations and individuals must stay informed about such threats and take proactive measures to safeguard their digital environments.
