Cybersecurity researchers have uncovered a sustained supply chain compromise targeting QuickFox, a virtual private network and network acceleration service primarily used by overseas Chinese communities. Active since at least August 2025, the campaign replaces legitimate software installers with trojanized versions that deploy a stealthy backdoor known as FDMTP.

Fortinet FortiGuard Labs detailed the findings in a report, identifying malicious activity embedded within the application’s official distribution channels. Instead of opportunistic phishing, threat actors infiltrated the software supply chain to distribute compromised Windows installers.

Once executed, the trojanized payload installs the FDMTP backdoor on victim machines. To evade detection, the malware is signed with a counterfeit Microsoft certificate and connects to a command-and-control server using a custom communication protocol. This setup allows operators to execute remote commands, exfiltrate files, and manipulate system configurations, with the bespoke protocol designed to bypass standard network monitoring.

The attack’s longevity and precise targeting suggest a highly resourced operation. By compromising a legitimate vendor’s distribution pipeline, attackers leveraged user trust for widespread deployment. QuickFox’s user base, which relies on the tool to bypass regional network restrictions, represents a concentrated demographic vulnerable to such manipulation. The campaign underscores how threat actors increasingly use trusted software vendors as force multipliers for large-scale compromise.

Several questions remain unanswered. FortiGuard Labs has not attributed the campaign to a specific group, and the exact number of compromised endpoints and geographic spread are under investigation. Security teams are working to map the breach’s scope and identify any secondary payloads or lateral movement.

For the IT community, this incident highlights the fragility of modern distribution ecosystems. Even established applications can become persistent threats when build environments or update servers are compromised. It reinforces the need for rigorous supply chain security, including reproducible builds, code-signing verification, and automated integrity checks. IT administrators should audit third-party tools, enforce allowlisting, and verify cryptographic signatures before deployment.

As investigations proceed, QuickFox users are advised to verify software authenticity and monitor for anomalous network traffic. The FDMTP campaign reminds us that trust in software vendors must be continuously validated through technical controls, not assumed.


網絡安全研究人員揭露一宗持續性供應鏈攻擊,目標為主要供海外華人社區使用的虛擬私人網絡及網絡加速服務QuickFox。該攻擊行動自至少2025年8月起活躍,透過將合法軟件安裝程式替換為植入特洛伊木馬的版本,部署名為FDMTP的隱蔽後門程式。

Fortinet FortiGuard實驗室在報告中詳細闡述調查結果,確認惡意活動嵌入於應用程式官方分發渠道內。威脅行為者並非透過機會式釣魚攻擊,而是滲透軟件供應鏈,傳播受感染的Windows安裝程式。

特洛伊木馬載荷執行後,會在受害者電腦上安裝FDMTP後門程式。為了避開偵測,該惡意軟件使用偽造的微軟證書簽署,並透過自訂通訊協議連接至指揮與控制伺服器。這種設計允許攻擊者執行遠端指令、竊取檔案及操控系統配置,專屬協議旨在繞過標準網絡監控。

攻擊的長期性及精準目標顯示這是一場資源充沛的行動。透過入侵合法供應商的分發管道,攻擊者利用用戶信任進行大規模部署。QuickFox的用戶群依賴該工具繞過區域網絡限制,構成容易受到此類操控的集中人群。此次事件突顯威脅行為者日益將可信軟件供應商作為大規模入侵的倍增器。

尚有若干疑點未獲解答。FortiGuard實驗室尚未將此次攻擊歸咎於特定組織,受感染端點的確切數量及地理分佈仍在調查中。安全團隊正著手釐清入侵範圍,並識別是否存在次級載荷或橫向移動。

對資訊科技界而言,此次事件暴露現代分發生態系的脆弱性。即使是成熟的應用程式,當構建環境或更新伺服器遭入侵時,也可能演變為持續性威脅。這再次強調了嚴格供應鏈安全措施的必要性,包括可重複構建、代碼簽章驗證及自動化完整性檢查。資訊科技管理員應審核第三方工具、強制執行白名單政策,並在部署前驗證加密簽名。

隨著調查持續進行,QuickFox用戶應驗證軟件真實性並監察異常網絡流量。FDMTP攻擊事件提醒我們,對軟件供應商的信任必須透過技術控制持續驗證,而非視為理所當然。

新聞來源 / Original News Source