QuickFox Loader Targets Only Chosen Windows Hosts

This campaign was built to hide in plain sight by refusing to run on most machines. The loader fingerprints the endpoint first, checks for specific software, and stops unless the host matches the intended profile, so a clean install does not mean a clean population. Fortinet says the trojanized QuickFox Windows installer has been active since at least August 2025 and delivered the FDMTP backdoor tied to Mustang Panda. QuickFox has released version 3.59.6 to remove the malicious components after responsible disclosure. The risk is a narrow but durable supply-chain path into a specific user base that already trusts the tool. Standard endpoint scans can miss it because only selected hosts ever show the full payload.

Part of the PlainSec briefing for 2026-08-05

Editions

Sources