
QuickFox VPN Targeted in Supply Chain Attack Delivering FDMTP Backdoor
CybersecuritySupplyChainAttacksMalwareVPNSecurity
Cybersecurity researchers at Fortinet FortiGuard Labs identified a supply chain attack targeting QuickFox, a VPN and network acceleration tool primarily used by overseas Chinese users. The attack has been active since at least August 2025 and involves a trojanized version of the QuickFox installer to deploy the FDMTP backdoor. No specific CVE IDs or additional technical details about the malware’s functionality were provided in the disclosed findings. The campaign exploits the software’s distribution mechanism to compromise users installing the legitimate-looking but malicious package.