
Summary
FDMTP is a modular backdoor delivered through a compromised version of QuickFox, a VPN and network accelerator popular with Chinese users living abroad. Active since at least August 2025, the FDMTP campaign added malicious JavaScript to trojanized Windows installers that fingerprint each device, avoid personal gaming machines, and selectively deploy the FDMTP implant onto machines showing signs of developer, financial, or translation software. Once installed, FDMTP profiles its host, reports back to a staging command server, and awaits additional plugins pushed down over a dedicated command-and-control channel. QuickFox has since removed the malicious code from its installer, though intelligence gaps remain around the FDMTP campaign’s full scope and intended targets.
Attack Details
A trojanized QuickFox installer as the entry point
FDMTP reaches victims through a compromised software supply chain rather than a phishing email or an exploited vulnerability. The target is QuickFox, a VPN and network accelerator used mainly by Chinese international students and expats. Attackers modified a legitimate Windows installer by adding malicious JavaScript into its Electron renderer HTML file. This tampered QuickFox installer circulated in builds from version 3.51.0 through 3.59.5, before the vendor removed the malicious code with version 3.59.6 following responsible disclosure.
Fingerprinting, filtering, and deploying the FDMTP implant
Once installed, the planted JavaScript reaches out to a look-alike domain designed to pass as QuickFox’s own infrastructure, then pulls down a second, heavily obfuscated script disguised as Firebase analytics code. That script checks whether the machine is running Windows, confirms with its command server that the device has not already been infected, then checks the running processes. If the popular game platform Steam is running, the FDMTP infection quietly stops; if instead a translation, financial, or developer tool is running, the script downloads a package pairing a legitimate Microsoft utility with a malicious companion file. The legitimate file loads its malicious counterpart, which decrypts and runs the final payload: an implant with fifteen internal modules known as FDMTP.
Host profiling instead of credential theft or lateral movement
This FDMTP campaign has not shown credential theft or movement between machines on a network. Instead, FDMTP gathers a detailed profile of its host, including installed antivirus software, network and operating system details, and the current username, then reports this back to its command infrastructure. A follow-up request lists every running process, likely helping FDMTP operators decide which infected devices are worth pursuing further. This points to a campaign still in its target-validation phase rather than actively spreading.
Staged command-and-control and modular plugin delivery
Communication with the FDMTP attackers occurs in two stages: a short web request to a staging domain to obtain command-server addresses, followed by a dedicated protocol for ongoing contact on ports in the 20800-20816 range. Through this channel, the command server can push additional plugin modules, store them in a registry key associated with the infected machine, and trigger them on demand. One observed plugin downloaded extra files to the machine, showing how FDMTP operators can extend the implant’s capabilities without updating the core payload.
Recommendations
Update QuickFox to a clean version
Upgrade all Windows installations of QuickFox to version 3.59.6 or later, the first release confirmed to have the trojanized installer components removed, eliminating the FDMTP infection vector at its source.
Verify installer integrity before deployment
For any QuickFox installer already downloaded, confirm its file hashes against known-clean releases before running it, since affected builds spanned versions 3.51.0 through 3.59.5 and could silently deploy the FDMTP backdoor.
Hunt for DLL side-loading via csmonitor.exe
Review endpoints for the legitimate Windows Azure Compute and Storage Emulator binary, csmonitor.exe, launching from non-standard paths such as the local temp directory, a strong signal of the side-loading technique used to load the FDMTP loader.
Extend scrutiny to personal-use software on corporate devices
Treat consumer VPN, proxy, and accelerator tools installed on work devices as part of the software supply chain risk surface, since the FDMTP campaign specifically leveraged one such tool, QuickFox, to reach corporate endpoints.
Establish a vetting process for third-party applications
Require security review of consumer-grade utilities before they are permitted on managed devices, particularly ones sourced outside a formal procurement or patch-management program.
Maintain backups isolated from production networks
Keep offline or segmented backups for endpoints in higher-risk categories, ensuring recovery options exist regardless of what a pushed FDMTP plugin ultimately does.
MITRE ATT&CK TTPs
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
| SHA256 | 2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C3BD3B300F3278520819A06D0CB1F0EADBF946DBBC11352538246FF075EB427F15CBB64375636E83B5F17D6083633CECC02E2A5F4168CD7CCA5CDEE36CCCA9B386634339B813E6105B5138DE6AB67B016B8DFBF49233C29DE9BAB3207E8B50D246932A20AC61FD3F93D7CFEE414F6F46834068AC7C9CA011B054A6A10DC56B3D17462CE2595119C928CF516EC33148DC2A39DD9F71636A5C849C7ED93B7C5CA06795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9A53D756F28457B1C4A239C91CDEC8ED7B7DA67A93E332E6DF9621CBEF8417474A5D36EDC34FE54B2092349F877DAF560A98F5FEA635D1AC4A110B3518102EF96D9DB5CBC193DDAF4C0A265804FDEF70C32451DAAF2974FA9ADF52CE1DEFAC5F7DC666E9C148BBCA5E21D8C9A97143575C075F53360F135E0191AED9E8278D396 |
| SHA1 | 11A6DF1E15663AE89F59A9E598AE8987F42A632B173DD4190740B96F6F733C801B6428ED4B52B6072CC0425A90A39AC4EEDADD59CAAAFAD5B50F84203449A349B6C8045B16DF4F88D58C65C2BDF891BB39504CEAD410056878962053F8D027E9F299CD107AB7FFE4C233A4F2440F0FDEB2E117C788792281A195810C41F401C4B48CB557CF8CE60C2D807025B194A997C9A653134BDB1F2D0C3137DCDACB54D5B370B674CE877B9C0A7708C7834AEB7EDA983564C41B4E11E6A9E3B53DA1F92B213DE9F65A825C92E90D2730F3354FF1ADF334B03C95EAC3207D47B9 |
| MD5 | 03FD832B81DD54D2BF5F610A8FF2785619E760EE849EB7C1F100F2B7010A763D1F3031167F94B166CC7B69376A01C1242DD8681DCD218C88D1C78DFE939EC92B2FFDCFB7157511789228988E26D06FD630D59C3D4916AA5FB24050C6AAE7F8E43B79D95F7F7B58C401A3BC79F94EBB525E4ED6ABBF555E5A542E3D4308CCD7BF5F3DAF7417DD666213168EB6C7453CC7B1D344C9A1525373BE6A3980FA85A603E0A92209DD62DAE8460D934DC6B7DDD7 |
| Domains | cdns3[.]51quickfox[.]cnwww[.]google-apis[.]netwww[.]icloud-cdn[.]netwww[.]techcheck1[.]comwww[.]wangmeng66[.]topwww[.]wangmeng[.]xyzwww[.]wangmengsb[.]comwww[.]yahoo-cdn[.]it[.]com |
| URLs | hxxp[:]//cdns3[.]51quickfox[.]cn/2025090411/update[.]ziphxxp[:]//www[.]icloud-cdn[.]net[:]8080/GetClusterhxxp[:]//www[.]icloud-cdn[.]net[:]8080/GetSlaverhxxps[:]//cdns3[.]51quickfox[.]cn/script/firebase-analytics-compat[.]jshxxps[:]//cdns3[.]51quickfox[.]cn/script/firebase-app-compat[.]jshxxps[:]//www[.]google-apis[.]net/dfsvc[.]exehxxps[:]//www[.]google-apis[.]net/dfsvc[.]exe[.]confighxxps[:]//www[.]google-apis[.]net/wangmeng[.]dllhxxps[:]//www[.]icloud-cdn[.]net/Client[.]dllhxxps[:]//www[.]icloud-cdn[.]net/checksum[.]binhxxps[:]//www[.]icloud-cdn[.]net/dnscfg[.]dllhxxps[:]//www[.]icloud-cdn[.]net/vshost[.]exehxxps[:]//www[.]techcheck1[.]com/GetClusterNodeshxxps[:]//www[.]techcheck1[.]com/GetPeershxxps[:]//www[.]techcheck1[.]com/Microsoft[.]VisualStudio[.]HostingProcess[.]Utilities[.]Sync[.]dllhxxps[:]//www[.]techcheck1[.]com/config[.]etlhxxps[:]//www[.]techcheck1[.]com/dfsvc[.]exe[.]confighxxps[:]//www[.]techcheck1[.]com/vshost[.]exehxxps[:]//www[.]techcheck1[.]com/wangmeng[.]dllhxxps[:]//www[.]wangmeng66[.]top/GetAddresseshxxps[:]//www[.]wangmeng66[.]top/GetEndpointshxxps[:]//www[.]wangmeng66[.]top/GetHostshxxps[:]//www[.]wangmeng66[.]top/GetInstanceshxxps[:]//www[.]wangmeng66[.]top/GetMachineshxxps[:]//www[.]wangmeng66[.]top/GetPeershxxps[:]//www[.]wangmeng66[.]top/GetProxieshxxps[:]//www[.]wangmeng66[.]top/GetReplicashxxps[:]//www[.]wangmeng66[.]top/GetResourceshxxps[:]//www[.]wangmeng66[.]top/GetRouteshxxps[:]//www[.]wangmeng66[.]top/GetServershxxps[:]//www[.]wangmeng66[.]top/GetTargetshxxps[:]//www[.]wangmeng66[.]top/GetWorkershxxps[:]//www[.]wangmeng[.]xyz/GetAgentshxxps[:]//www[.]wangmeng[.]xyz/GetEndpointshxxps[:]//www[.]wangmeng[.]xyz/GetInstanceshxxps[:]//www[.]wangmeng[.]xyz/GetMachineshxxps[:]//www[.]wangmeng[.]xyz/GetMembershxxps[:]//www[.]wangmeng[.]xyz/GetNodeshxxps[:]//www[.]wangmeng[.]xyz/GetPeershxxps[:]//www[.]wangmeng[.]xyz/GetReplicashxxps[:]//www[.]wangmeng[.]xyz/GetRouteshxxps[:]//www[.]wangmeng[.]xyz/GetServershxxps[:]//www[.]wangmeng[.]xyz/GetTargetshxxps[:]//www[.]wangmeng[.]xyz/GetVipshxxps[:]//www[.]wangmeng[.]xyz/GetWorkershxxps[:]//www[.]wangmengsb[.]com/GetAddresseshxxps[:]//www[.]wangmengsb[.]com/GetAgentshxxps[:]//www[.]wangmengsb[.]com/GetBackendshxxps[:]//www[.]wangmengsb[.]com/GetHostshxxps[:]//www[.]wangmengsb[.]com/GetIpshxxps[:]//www[.]wangmengsb[.]com/GetNodeshxxps[:]//www[.]wangmengsb[.]com/GetPeershxxps[:]//www[.]wangmengsb[.]com/GetReplicashxxps[:]//www[.]wangmengsb[.]com/GetRouteshxxps[:]//www[.]wangmengsb[.]com/GetServershxxps[:]//www[.]wangmengsb[.]com/GetVipshxxps[:]//www[.]wangmengsb[.]com/GetWorkershxxps[:]//www[.]yahoo-cdn[.]it[.]com/GetClusterhxxps[:]//www[.]yahoo-cdn[.]it[.]com/Microsoft[.]VisualStudio[.]HostingProcess[.]Utilities[.]Sync[.]dllhxxps[:]//www[.]yahoo-cdn[.]it[.]com/config[.]etlhxxps[:]//www[.]yahoo-cdn[.]it[.]com/dfsvc[.]exehxxps[:]//www[.]yahoo-cdn[.]it[.]com/dfsvc[.]exe[.]confighxxps[:]//www[.]yahoo-cdn[.]it[.]com/dnscfg[.]dllhxxps[:]//www[.]yahoo-cdn[.]it[.]com/vshost[.]exe |
| IPv4 | 38[.]60[.]142[.]5643[.]240[.]12[.]3443[.]240[.]12[.]3545[.]125[.]15[.]10045[.]125[.]15[.]10445[.]125[.]15[.]11145[.]125[.]15[.]11445[.]125[.]15[.]11545[.]125[.]35[.]22545[.]125[.]35[.]22645[.]125[.]35[.]22745[.]125[.]35[.]22945[.]125[.]35[.]23045[.]125[.]35[.]23145[.]125[.]35[.]23245[.]125[.]35[.]23345[.]125[.]35[.]23445[.]125[.]35[.]23545[.]125[.]35[.]23645[.]158[.]180[.]25047[.]76[.]92[.]7347[.]83[.]122[.]5147[.]86[.]14[.]2247[.]88[.]21[.]25247[.]238[.]64[.]5647[.]238[.]240[.]21947[.]239[.]4[.]17947[.]239[.]93[.]49103[.]231[.]15[.]135103[.]231[.]15[.]219103[.]231[.]15[.]248103[.]246[.]244[.]13103[.]246[.]244[.]20104[.]21[.]7[.]138104[.]21[.]37[.]164104[.]21[.]39[.]112104[.]21[.]44[.]82104[.]21[.]89[.]96104[.]21[.]95[.]64123[.]254[.]105[.]38123[.]254[.]106[.]148154[.]223[.]24[.]158154[.]223[.]54[.]159154[.]223[.]58[.]64154[.]223[.]58[.]142154[.]223[.]75[.]206170[.]33[.]128[.]5172[.]67[.]135[.]248172[.]67[.]143[.]103172[.]67[.]144[.]222172[.]67[.]157[.]196172[.]67[.]197[.]227172[.]67[.]210[.]148202[.]181[.]25[.]71202[.]181[.]25[.]73 |
| Filenames | Assist.dllClient.dllMicrosoft.ServiceHosting.Tools.dllconfig.bincsmonitor.exedata.datfirebase-analytics-compat.jsfirebase-app-compat.jsindex.htmlupdate.binupdate.zip |
| File Path | %TEMP%\quickfox\update.zip%APPDATA%\Local\Temp\quickfox\updated\%LocalAppData%\Microsoft\WindowsApps |
References & Patch Links
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.