A Fake Update, a Real Threat: The FDMTP Backdoor's Supply Chain Run

Amber | Attack
Download PDF
TA2026222 | FDMTP Backdoor Hides in a Trojanized QuickFox VPN Installer

FDMTP Backdoor Rides a Trojanized QuickFox VPN Installer Into Victim Networks

FDMTP is a modular backdoor delivered through a compromised version of QuickFox, a VPN and network accelerator popular with Chinese users living abroad. Active since at least August 2025, the FDMTP campaign added malicious JavaScript to trojanized Windows installers that fingerprint each device, avoid personal gaming machines, and selectively deploy the FDMTP implant onto machines showing signs of developer, financial, or translation software. Once installed, FDMTP profiles its host, reports back to a staging command server, and awaits additional plugins pushed down over a dedicated command-and-control channel. QuickFox has since removed the malicious code from its installer, though intelligence gaps remain around the FDMTP campaign’s full scope and intended targets.


How the FDMTP Backdoor Compromises QuickFox VPN Installations

1

A trojanized QuickFox installer as the entry point

FDMTP reaches victims through a compromised software supply chain rather than a phishing email or an exploited vulnerability. The target is QuickFox, a VPN and network accelerator used mainly by Chinese international students and expats. Attackers modified a legitimate Windows installer by adding malicious JavaScript into its Electron renderer HTML file. This tampered QuickFox installer circulated in builds from version 3.51.0 through 3.59.5, before the vendor removed the malicious code with version 3.59.6 following responsible disclosure.

2

Fingerprinting, filtering, and deploying the FDMTP implant

Once installed, the planted JavaScript reaches out to a look-alike domain designed to pass as QuickFox’s own infrastructure, then pulls down a second, heavily obfuscated script disguised as Firebase analytics code. That script checks whether the machine is running Windows, confirms with its command server that the device has not already been infected, then checks the running processes. If the popular game platform Steam is running, the FDMTP infection quietly stops; if instead a translation, financial, or developer tool is running, the script downloads a package pairing a legitimate Microsoft utility with a malicious companion file. The legitimate file loads its malicious counterpart, which decrypts and runs the final payload: an implant with fifteen internal modules known as FDMTP.

3

Host profiling instead of credential theft or lateral movement

This FDMTP campaign has not shown credential theft or movement between machines on a network. Instead, FDMTP gathers a detailed profile of its host, including installed antivirus software, network and operating system details, and the current username, then reports this back to its command infrastructure. A follow-up request lists every running process, likely helping FDMTP operators decide which infected devices are worth pursuing further. This points to a campaign still in its target-validation phase rather than actively spreading.

4

Staged command-and-control and modular plugin delivery

Communication with the FDMTP attackers occurs in two stages: a short web request to a staging domain to obtain command-server addresses, followed by a dedicated protocol for ongoing contact on ports in the 20800-20816 range. Through this channel, the command server can push additional plugin modules, store them in a registry key associated with the infected machine, and trigger them on demand. One observed plugin downloaded extra files to the machine, showing how FDMTP operators can extend the implant’s capabilities without updating the core payload.


Patching and Hardening Against the FDMTP Backdoor

1

Update QuickFox to a clean version

Upgrade all Windows installations of QuickFox to version 3.59.6 or later, the first release confirmed to have the trojanized installer components removed, eliminating the FDMTP infection vector at its source.

2

Verify installer integrity before deployment

For any QuickFox installer already downloaded, confirm its file hashes against known-clean releases before running it, since affected builds spanned versions 3.51.0 through 3.59.5 and could silently deploy the FDMTP backdoor.

3

Hunt for DLL side-loading via csmonitor.exe

Review endpoints for the legitimate Windows Azure Compute and Storage Emulator binary, csmonitor.exe, launching from non-standard paths such as the local temp directory, a strong signal of the side-loading technique used to load the FDMTP loader.

4

Extend scrutiny to personal-use software on corporate devices

Treat consumer VPN, proxy, and accelerator tools installed on work devices as part of the software supply chain risk surface, since the FDMTP campaign specifically leveraged one such tool, QuickFox, to reach corporate endpoints.

5

Establish a vetting process for third-party applications

Require security review of consumer-grade utilities before they are permitted on managed devices, particularly ones sourced outside a formal procurement or patch-management program.

6

Maintain backups isolated from production networks

Keep offline or segmented backups for endpoints in higher-risk categories, ensuring recovery options exist regardless of what a pushed FDMTP plugin ultimately does.


Potential MITRE ATT&CK TTPs

T1195 / T1195.002
Initial Access
Supply Chain Compromise — Compromise Software Supply Chain
T1059 / T1059.007
Execution
Command and Scripting Interpreter — JavaScript
T1027
Defense Evasion
Obfuscated Files or Information
T1140
Defense Evasion
Deobfuscate/Decode Files or Information
T1574 / T1574.001
Defense Evasion
Hijack Execution Flow — DLL
T1036 / T1036.005
Defense Evasion
Masquerading — Match Legitimate Resource Name or Location
T1480
Defense Evasion
Execution Guardrails
T1112
Persistence
Modify Registry
T1057
Discovery
Process Discovery
T1082
Discovery
System Information Discovery
T1016
Discovery
System Network Configuration Discovery
T1033
Discovery
System Owner/User Discovery
T1071 / T1071.001
Command and Control
Application Layer Protocol — Web Protocols
T1104
Command and Control
Multi-Stage Channels

FDMTP Backdoor Indicators of Compromise

Type Value
SHA256 2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C3BD3B300F3278520819A06D0CB1F0EADBF946DBBC11352538246FF075EB427F15CBB64375636E83B5F17D6083633CECC02E2A5F4168CD7CCA5CDEE36CCCA9B386634339B813E6105B5138DE6AB67B016B8DFBF49233C29DE9BAB3207E8B50D246932A20AC61FD3F93D7CFEE414F6F46834068AC7C9CA011B054A6A10DC56B3D17462CE2595119C928CF516EC33148DC2A39DD9F71636A5C849C7ED93B7C5CA06795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9A53D756F28457B1C4A239C91CDEC8ED7B7DA67A93E332E6DF9621CBEF8417474A5D36EDC34FE54B2092349F877DAF560A98F5FEA635D1AC4A110B3518102EF96D9DB5CBC193DDAF4C0A265804FDEF70C32451DAAF2974FA9ADF52CE1DEFAC5F7DC666E9C148BBCA5E21D8C9A97143575C075F53360F135E0191AED9E8278D396
SHA1 11A6DF1E15663AE89F59A9E598AE8987F42A632B173DD4190740B96F6F733C801B6428ED4B52B6072CC0425A90A39AC4EEDADD59CAAAFAD5B50F84203449A349B6C8045B16DF4F88D58C65C2BDF891BB39504CEAD410056878962053F8D027E9F299CD107AB7FFE4C233A4F2440F0FDEB2E117C788792281A195810C41F401C4B48CB557CF8CE60C2D807025B194A997C9A653134BDB1F2D0C3137DCDACB54D5B370B674CE877B9C0A7708C7834AEB7EDA983564C41B4E11E6A9E3B53DA1F92B213DE9F65A825C92E90D2730F3354FF1ADF334B03C95EAC3207D47B9
MD5 03FD832B81DD54D2BF5F610A8FF2785619E760EE849EB7C1F100F2B7010A763D1F3031167F94B166CC7B69376A01C1242DD8681DCD218C88D1C78DFE939EC92B2FFDCFB7157511789228988E26D06FD630D59C3D4916AA5FB24050C6AAE7F8E43B79D95F7F7B58C401A3BC79F94EBB525E4ED6ABBF555E5A542E3D4308CCD7BF5F3DAF7417DD666213168EB6C7453CC7B1D344C9A1525373BE6A3980FA85A603E0A92209DD62DAE8460D934DC6B7DDD7
Domains cdns3[.]51quickfox[.]cnwww[.]google-apis[.]netwww[.]icloud-cdn[.]netwww[.]techcheck1[.]comwww[.]wangmeng66[.]topwww[.]wangmeng[.]xyzwww[.]wangmengsb[.]comwww[.]yahoo-cdn[.]it[.]com
URLs hxxp[:]//cdns3[.]51quickfox[.]cn/2025090411/update[.]ziphxxp[:]//www[.]icloud-cdn[.]net[:]8080/GetClusterhxxp[:]//www[.]icloud-cdn[.]net[:]8080/GetSlaverhxxps[:]//cdns3[.]51quickfox[.]cn/script/firebase-analytics-compat[.]jshxxps[:]//cdns3[.]51quickfox[.]cn/script/firebase-app-compat[.]jshxxps[:]//www[.]google-apis[.]net/dfsvc[.]exehxxps[:]//www[.]google-apis[.]net/dfsvc[.]exe[.]confighxxps[:]//www[.]google-apis[.]net/wangmeng[.]dllhxxps[:]//www[.]icloud-cdn[.]net/Client[.]dllhxxps[:]//www[.]icloud-cdn[.]net/checksum[.]binhxxps[:]//www[.]icloud-cdn[.]net/dnscfg[.]dllhxxps[:]//www[.]icloud-cdn[.]net/vshost[.]exehxxps[:]//www[.]techcheck1[.]com/GetClusterNodeshxxps[:]//www[.]techcheck1[.]com/GetPeershxxps[:]//www[.]techcheck1[.]com/Microsoft[.]VisualStudio[.]HostingProcess[.]Utilities[.]Sync[.]dllhxxps[:]//www[.]techcheck1[.]com/config[.]etlhxxps[:]//www[.]techcheck1[.]com/dfsvc[.]exe[.]confighxxps[:]//www[.]techcheck1[.]com/vshost[.]exehxxps[:]//www[.]techcheck1[.]com/wangmeng[.]dllhxxps[:]//www[.]wangmeng66[.]top/GetAddresseshxxps[:]//www[.]wangmeng66[.]top/GetEndpointshxxps[:]//www[.]wangmeng66[.]top/GetHostshxxps[:]//www[.]wangmeng66[.]top/GetInstanceshxxps[:]//www[.]wangmeng66[.]top/GetMachineshxxps[:]//www[.]wangmeng66[.]top/GetPeershxxps[:]//www[.]wangmeng66[.]top/GetProxieshxxps[:]//www[.]wangmeng66[.]top/GetReplicashxxps[:]//www[.]wangmeng66[.]top/GetResourceshxxps[:]//www[.]wangmeng66[.]top/GetRouteshxxps[:]//www[.]wangmeng66[.]top/GetServershxxps[:]//www[.]wangmeng66[.]top/GetTargetshxxps[:]//www[.]wangmeng66[.]top/GetWorkershxxps[:]//www[.]wangmeng[.]xyz/GetAgentshxxps[:]//www[.]wangmeng[.]xyz/GetEndpointshxxps[:]//www[.]wangmeng[.]xyz/GetInstanceshxxps[:]//www[.]wangmeng[.]xyz/GetMachineshxxps[:]//www[.]wangmeng[.]xyz/GetMembershxxps[:]//www[.]wangmeng[.]xyz/GetNodeshxxps[:]//www[.]wangmeng[.]xyz/GetPeershxxps[:]//www[.]wangmeng[.]xyz/GetReplicashxxps[:]//www[.]wangmeng[.]xyz/GetRouteshxxps[:]//www[.]wangmeng[.]xyz/GetServershxxps[:]//www[.]wangmeng[.]xyz/GetTargetshxxps[:]//www[.]wangmeng[.]xyz/GetVipshxxps[:]//www[.]wangmeng[.]xyz/GetWorkershxxps[:]//www[.]wangmengsb[.]com/GetAddresseshxxps[:]//www[.]wangmengsb[.]com/GetAgentshxxps[:]//www[.]wangmengsb[.]com/GetBackendshxxps[:]//www[.]wangmengsb[.]com/GetHostshxxps[:]//www[.]wangmengsb[.]com/GetIpshxxps[:]//www[.]wangmengsb[.]com/GetNodeshxxps[:]//www[.]wangmengsb[.]com/GetPeershxxps[:]//www[.]wangmengsb[.]com/GetReplicashxxps[:]//www[.]wangmengsb[.]com/GetRouteshxxps[:]//www[.]wangmengsb[.]com/GetServershxxps[:]//www[.]wangmengsb[.]com/GetVipshxxps[:]//www[.]wangmengsb[.]com/GetWorkershxxps[:]//www[.]yahoo-cdn[.]it[.]com/GetClusterhxxps[:]//www[.]yahoo-cdn[.]it[.]com/Microsoft[.]VisualStudio[.]HostingProcess[.]Utilities[.]Sync[.]dllhxxps[:]//www[.]yahoo-cdn[.]it[.]com/config[.]etlhxxps[:]//www[.]yahoo-cdn[.]it[.]com/dfsvc[.]exehxxps[:]//www[.]yahoo-cdn[.]it[.]com/dfsvc[.]exe[.]confighxxps[:]//www[.]yahoo-cdn[.]it[.]com/dnscfg[.]dllhxxps[:]//www[.]yahoo-cdn[.]it[.]com/vshost[.]exe
IPv4 38[.]60[.]142[.]5643[.]240[.]12[.]3443[.]240[.]12[.]3545[.]125[.]15[.]10045[.]125[.]15[.]10445[.]125[.]15[.]11145[.]125[.]15[.]11445[.]125[.]15[.]11545[.]125[.]35[.]22545[.]125[.]35[.]22645[.]125[.]35[.]22745[.]125[.]35[.]22945[.]125[.]35[.]23045[.]125[.]35[.]23145[.]125[.]35[.]23245[.]125[.]35[.]23345[.]125[.]35[.]23445[.]125[.]35[.]23545[.]125[.]35[.]23645[.]158[.]180[.]25047[.]76[.]92[.]7347[.]83[.]122[.]5147[.]86[.]14[.]2247[.]88[.]21[.]25247[.]238[.]64[.]5647[.]238[.]240[.]21947[.]239[.]4[.]17947[.]239[.]93[.]49103[.]231[.]15[.]135103[.]231[.]15[.]219103[.]231[.]15[.]248103[.]246[.]244[.]13103[.]246[.]244[.]20104[.]21[.]7[.]138104[.]21[.]37[.]164104[.]21[.]39[.]112104[.]21[.]44[.]82104[.]21[.]89[.]96104[.]21[.]95[.]64123[.]254[.]105[.]38123[.]254[.]106[.]148154[.]223[.]24[.]158154[.]223[.]54[.]159154[.]223[.]58[.]64154[.]223[.]58[.]142154[.]223[.]75[.]206170[.]33[.]128[.]5172[.]67[.]135[.]248172[.]67[.]143[.]103172[.]67[.]144[.]222172[.]67[.]157[.]196172[.]67[.]197[.]227172[.]67[.]210[.]148202[.]181[.]25[.]71202[.]181[.]25[.]73
Filenames Assist.dllClient.dllMicrosoft.ServiceHosting.Tools.dllconfig.bincsmonitor.exedata.datfirebase-analytics-compat.jsfirebase-app-compat.jsindex.htmlupdate.binupdate.zip
File Path %TEMP%\quickfox\update.zip%APPDATA%\Local\Temp\quickfox\updated\%LocalAppData%\Microsoft\WindowsApps

References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.