🟠 High  |  Source: The Hacker News


A trojanised version of QuickFox, a VPN tool popular with overseas Chinese users, has been used to deliver a backdoor called FDMTP in a supply chain attack active since at least August 2025. Attackers compromised the Windows installer to silently deploy malware alongside the legitimate application. Supply chain attacks of this nature are particularly dangerous because users trust the software source and security tools may not flag a signed or expected installer.

Security Architect’s Take: Audit your organisation’s approved software list for QuickFox or similar niche VPN tools, and enforce application allowlisting and binary integrity checks on all Windows endpoints. Consider blocking installer execution from unmanaged or personal devices that access corporate cloud resources, and ensure endpoint detection tooling covers post-installation backdoor behaviour such as FDMTP’s C2 communications.

Original advisory: QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer