< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-05T11:17:19+05:30

QuickFox Supply Chain Attack Exploits Trojanized Installer to Deploy FDMTP Backdoor

Cybersecurity researchers uncovered a supply chain attack on QuickFox, a VPN tool, where a trojanized Windows installer delivered the FDMTP backdoor. The attack, linked to Mustang Panda, used JavaScript payloads and DLL side-loading to target Windows users, evading detection through domain spoofing.

Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.

According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a

Read original article

*** END OF TRANSMISSION ***