By Interestana AI Editorial — AI-drafted, human-overseen. How we report
QuickFox Supply Chain Attack Delivers FDMTP Backdoor

Cybersecurity researchers have disclosed a "long-standing supply chain attack" targeting QuickFox, a virtual private network (VPN) and network acceleration tool primarily used by overseas Chinese users. Fortinet FortiGuard Labs reported on March 18, 2024, that this attack has been active since at least August 2025. The attackers achieved this by distributing a trojanized version of the QuickFox application, which was disguised as a legitimate Windows installer. This malicious installer was designed to deliver a backdoor known as FDMTP (also referred to as "Fast Data Transfer Protocol" or "FDMTP backdoor").
The FDMTP backdoor is a sophisticated piece of malware capable of performing a range of malicious activities on compromised systems. Its functionalities include downloading and executing arbitrary code, enabling remote access for attackers, and potentially exfiltrating sensitive data. The supply chain attack vector is particularly concerning because it leverages the trust users place in legitimate software updates and installations. By compromising the distribution channel of QuickFox, the attackers could reach a wide audience of unsuspecting users who believed they were installing or updating a trusted application. The ongoing nature of the attack since August 2025 suggests a persistent and well-resourced threat actor.
Fortinet's analysis indicates that the initial infection vector involved a malicious Windows installer file for the QuickFox application. This installer contained embedded malware that, upon execution, would install the FDMTP backdoor onto the victim's system. The researchers have not yet specified the exact method by which the QuickFox installer itself was compromised, but the implication is that the attackers gained access to the software's build or distribution pipeline. This allowed them to replace the legitimate installer with their malicious version, effectively turning a trusted software into a delivery mechanism for malware. The FDMTP backdoor's capabilities are typical of advanced persistent threats (APTs), which often aim for long-term access and stealthy operations.
The discovery highlights the persistent threat posed by supply chain attacks, which have become a favored tactic for cybercriminals and nation-state actors alike. These attacks exploit vulnerabilities in the software development and distribution process, making them difficult to detect and defend against. Users of QuickFox, particularly those who downloaded the application around or after August 2025, are advised to exercise extreme caution and consider scanning their systems for the presence of the FDMTP backdoor. Further investigation by cybersecurity firms is likely to reveal more details about the specific techniques used by the attackers and the full scope of the compromise.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.