Fortinet FortiGuard Labs has disclosed a supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese users. The attack has operated since at least August 2025, distributing trojanized Windows installers that deliver FDMTP, a previously undocumented backdoor.

The attack chain exploits QuickFox's legitimate distribution mechanism. Attackers compromised the software supply chain to inject malicious code into official installers. Users downloading what appeared to be the legitimate QuickFox application unknowingly installed FDMTP alongside it. The backdoor operates silently within infected systems, establishing persistent remote access for threat actors.

FDMTP functions as a full-featured backdoor, enabling attackers to execute arbitrary commands, exfiltrate data, and maintain long-term control over compromised machines. The backdoor's capabilities allow threat actors to conduct espionage, steal credentials, or use infected systems as launching points for further attacks within organizational networks.

The targeting of QuickFox specifically reflects a focused strategy. The application's user base concentrates on overseas Chinese communities and businesses, making it an efficient vector for targeting specific geographic or demographic populations. Supply chain attacks of this nature prove particularly damaging because they bypass traditional security awareness and exploit user trust in known applications.

Organizations and individuals using QuickFox should immediately verify their installed version against official checksums and revoke any trust granted to potentially compromised installations. Network administrators should scan systems for FDMTP indicators of compromise, including network connections to attacker-controlled infrastructure and suspicious process execution patterns. Users should uninstall suspicious versions and download fresh copies directly from QuickFox's official website, verifying file integrity afterward.

The timing of disclosure in late 2025 suggests the attack operated undetected for months, potentially affecting thousands of users. The use of a previously unknown