QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor

Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Table of Contents
    Add a header to begin generating the table of contents

    Fortinet’s FortiGuard Labs has disclosed a long-running supply-chain attack on QuickFox, a VPN and network-acceleration tool designed for overseas Chinese users, in which a trojanized version of the application installs a previously undocumented backdoor called FDMTP. The malicious build is distributed through the tool’s own distribution channel, which makes it difficult for users to distinguish a legitimate installer from a compromised one, according to Fortinet’s research.

    How the Trojanized QuickFox Installer Delivers the FDMTP Backdoor

    FortiGuard Labs said the supply-chain compromise has been ongoing since at least the previous year and involves a trojanized Windows installer that, when run, drops the FDMTP backdoor onto the victim’s system. Because the malicious payload travels through the same distribution channel QuickFox itself uses, the researchers noted that end users have no easy way to tell whether the copy they downloaded is genuine.

    Why a Compromised Distribution Channel Is Difficult to Detect

    The central problem in this attack is trust: a VPN vendor’s own download site is precisely where users would expect to find the legitimate product, so a trojanized build served from that channel blends into normal behavior. Fortinet detailed technical indicators for FDMTP so users can scan for signs of the backdoor, and advised that anyone who downloaded QuickFox verify the integrity of the installer.

    What the FDMTP Backdoor Means for QuickFox and VPN Users

    The attack takes on added weight because of what a VPN tool is used for. Users of QuickFox are typically trying to accelerate or secure network connections, which means the device may handle sensitive traffic, and a backdoor on the same system gives the attacker persistent remote access underneath that trusted connection. The exposure risk is compounded by the fact that the compromise is long-standing, so a large population of users may have installed an infected build without knowing it.

    The Persistent Remote-Access Risk From FDMTP

    Fortinet characterized FDMTP as a backdoor that grants an attacker ongoing remote access to the affected system. For a VPN product that was itself selected to protect a user’s activity, that level of access inverts the tool’s purpose: the very software meant to secure the connection becomes the channel by which an attacker retains a foothold.

    Why the QuickFox Compromise Points to a Broader Trend

    The disclosure follows a pattern in which threat actors compromise the legitimate software distribution of a targeted vendor rather than rely on fake or typosquatted downloads. A trojanized installer served from the vendor’s own channel defeats signature-based detection that flags unusual download sources, and it inherits whatever code-signing and brand trust the legitimate product carries.

    The Overseas-Chinese User Base and the Threat Landscape

    QuickFox is specifically marketed to overseas Chinese users, a population that often relies on such tools to reach services and content from home. That targeting profile matters because it means the infected builds reached users whose network activity the backdoor could observe and control directly, and because the users themselves may be less likely to question a download from the tool’s own distribution channel. Fortinet’s research described the operation as long-standing, having run for months, which suggests the trojanized builds circulated for a sustained period before disclosure.

    The Previously Undocumented Nature of FDMTP

    FortiGuard Labs identified FDMTP as a previously undocumented backdoor, meaning no prior analysis existed to help defenders recognize it. Undocumented malware in a supply-chain installer is a compounding problem: not only did the victims have no reason to distrust the download, but the security community had no signature, behavioral profile, or threat-intelligence coverage for the payload itself, leaving detection to luck until the disclosure.

    For VPN users and the vendors that ship these tools, the practical consequence is that installer authenticity cannot be assumed even from an official source. Fortinet’s guidance to verify installer integrity and scan for FDMTP indicators is the immediate response, but the deeper lesson is that supply-chain assurance has to include the distribution link itself, not just the final binary.

    The long-running nature of the QuickFox compromise also raises a question the researchers did not fully answer: how many other VPN and network tools are quietly shipping trojanized builds through their own channels, and how long can such an operation persist before it is discovered. For a sector whose entire value proposition is built on trust and user confidence, that uncertainty is as significant as the FDMTP backdoor itself.

    Related Posts