QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Overview
Cybersecurity researchers have identified a supply chain attack targeting QuickFox, a VPN tool favored by overseas Chinese users. The attack has reportedly been active since at least August 2025, involving a compromised version of the application that delivers the FDMTP backdoor. This backdoor allows attackers to gain unauthorized access to affected systems, posing significant risks to user privacy and data security. This incident raises concerns about the security of software supply chains, particularly for tools that are essential for users in sensitive environments. Users of QuickFox should be vigilant and consider alternative solutions while the situation is investigated further.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: QuickFox VPN tool, FDMTP backdoor
- Action Required: Users are advised to stop using QuickFox and look for alternative VPN solutions.
- Timeline: Ongoing since August 2025
Original Article Summary
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a
Impact
QuickFox VPN tool, FDMTP backdoor
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since August 2025
Remediation
Users are advised to stop using QuickFox and look for alternative VPN solutions. Further investigation is needed to determine specific patches or updates.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, Microsoft, Fortinet.