Threats & Adversaries · Supply Chain
QuickFox Loader Targets Only Chosen Windows Hosts This campaign was built to hide in plain sight by refusing to run on most machines. The loader fingerprints the endpoint first, checks for specific software, and stops unless the host matches the intended profile, so a clean install does not mean a clean population.
Fortinet says the trojanized QuickFox Windows installer has been active since at least August 2025 and delivered the FDMTP backdoor tied to Mustang Panda. QuickFox has released version 3.59.6 to remove the malicious components after responsible disclosure.
The risk is a narrow but durable supply-chain path into a specific user base that already trusts the tool. Standard endpoint scans can miss it because only selected hosts ever show the full payload.
2 sources · Aug 7
Timeline Sources Aug 7 Fortinet Outbreak Alerts
QuickFox Supply Chain Attack | Outbreak Alert | FortiGuard Labs
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily u...
original Aug 5 The Hacker News
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after profiling selected endpoints
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-08-06
Every edition of this story: QuickFox Loader Targets Only Chosen Windows Hosts
More from today
Threats & Adversaries · Supply Chain
QuickFox Loader Targets Only Chosen Windows Hosts This campaign was built to hide in plain sight by refusing to run on most machines. The loader fingerprints the endpoint first, checks for specific software, and stops unless the host matches the intended profile, so a clean install does not mean a clean population.
Fortinet says the trojanized QuickFox Windows installer has been active since at least August 2025 and delivered the FDMTP backdoor tied to Mustang Panda. QuickFox has released version 3.59.6 to remove the malicious components after responsible disclosure.
The risk is a narrow but durable supply-chain path into a specific user base that already trusts the tool. Standard endpoint scans can miss it because only selected hosts ever show the full payload.
2 sources · Aug 7
Timeline Sources Aug 7 Fortinet Outbreak Alerts
QuickFox Supply Chain Attack | Outbreak Alert | FortiGuard Labs
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily u...
original Aug 5 The Hacker News
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after profiling selected endpoints
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-08-06
Every edition of this story: QuickFox Loader Targets Only Chosen Windows Hosts
More from today