QuickFox Supply Chain Attack

FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access. The campaign has reportedly been active since August 2025 before being publicly disclosed in August 2026.