Active Exploitation Alert: QuickFox Windows Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Installer

Active Exploitation Alert: QuickFox Windows Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Installer

Executive Summary

A highly sophisticated supply chain attack has been identified targeting the QuickFox VPN/game accelerator for Windows, leveraging a trojanized installer to deliver the FDMTP backdoor. This campaign, active since at least August 2026, demonstrates advanced adversarial tradecraft, including selective victim targeting, process-based guardrails, and multi-stage payload delivery. The attackers injected malicious JavaScript into the official QuickFox Windows installer, which then conditionally deployed the FDMTP modular implant only on systems meeting specific criteria. The operation’s infrastructure and techniques overlap with those attributed to the advanced persistent threat group Twill Typhoon. The attack’s sophistication, targeting of high-value users (such as IT administrators, developers, and cryptocurrency users), and use of supply chain compromise underscore the critical risk to organizations relying on third-party software.

Threat Actor Profile

The campaign’s technical and operational characteristics strongly suggest attribution to the Twill Typhoon APT group, a threat actor known for targeting Chinese-speaking professionals, expatriates, and organizations with ties to China. Twill Typhoon is recognized for its use of supply chain attacks, custom backdoors, and advanced victim filtering mechanisms. The group’s infrastructure, including command-and-control (C2) domains and the bespoke FDMTP protocol, has been observed in previous campaigns. Their operational security is notable, with the use of typosquatted domains, legitimate binaries for DLL sideloading, and process-based guardrails to avoid detection and maximize operational impact. The targeting of users with administrative, development, translation, or cryptocurrency applications further aligns with Twill Typhoon’s historical victimology.

Technical Analysis of Malware/TTPs

The infection chain begins with a trojanized QuickFox Windows installer, where malicious JavaScript is injected into the index.html file within the Electron application archive (app.asar). Upon execution, this JavaScript loader downloads two additional scripts from the attacker-controlled domain cdns3[.]51quickfox[.]cn. The loader performs detailed victim fingerprinting, first verifying the operating system is Windows, then enumerating running processes using tasklist. If steam.exe is detected, the infection halts, likely to avoid personal or gaming systems. The loader proceeds only if one of 26 targeted applications is running, including SSH clients (such as xshell, finalshell, MobaXterm, Tabby), database tools (navicat, dbeaver), integrated development environments (idea64.exe, Code.exe), cryptocurrency wallets (Exodus.exe, Binance.exe, Ledger, Trezor), and translation tools (爱翻译, HelloWorld, Hello-GPT.exe, 海王出海, 易翻译, CC翻译, 快翻译, posend, 海译通.exe).

If the victim matches the targeting criteria, the loader downloads update.zip from the C2, extracts it to %APPDATA%\Local\Temp\quickfox\updated\, and executes csmonitor.exe (a legitimate Microsoft binary) to sideload the malicious Microsoft.ServiceHosting.Tools.dll. Two generations of the FDMTP implant have been observed. Generation 1 embeds the payload directly within the DLL, while Generation 2 decrypts and loads the payload from update.bin using AES-128-ECB with the key POt_L[Bsh0=+@0a.. The implant registers with the C2, receives additional plugins, and can execute arbitrary code, providing persistent and flexible access to compromised systems.

The C2 infrastructure utilizes both web protocols for initial registration (with domains such as www[.]icloud-cdn[.]net and www[.]google-apis[.]net) and the custom FDMTP protocol for persistent communication over ports 20800–20816. Plugins and further payloads are delivered via this channel, enabling modular post-exploitation capabilities. The attackers employ multiple layers of defense evasion, including DLL sideloading, registry-based persistence, and execution guardrails based on process enumeration.

Exploitation in the Wild

The campaign has been active since at least August 2026, with infections observed in organizations employing Chinese-speaking staff or utilizing QuickFox for VPN or game acceleration. The attack is highly selective, focusing on Windows endpoints where targeted administrative, development, translation, or cryptocurrency applications are present. There is no evidence of mass exploitation on macOS, iOS, or Android platforms, as the loader includes platform guardrails to prevent progression of the infection chain on non-Windows systems. The use of process-based filtering ensures that only high-value targets are compromised, reducing the likelihood of detection and maximizing the operational value of each infection.

Victimology and Targeting

The primary victims are users of the QuickFox Windows application who also run high-value software such as SSH clients, database management tools, IDEs, cryptocurrency wallets, and translation utilities. The targeting logic is implemented via process enumeration, with infection proceeding only if specific processes are detected. This approach suggests a focus on IT administrators, software developers, translators, cryptocurrency users, and professionals using Chinese-language tools. The campaign appears to be tailored towards Chinese-speaking professionals, expatriates, and international students, particularly those operating outside China or interacting with Chinese services. The selective targeting and advanced filtering mechanisms indicate a high degree of operational discipline and a clear intent to compromise only strategically valuable systems.

Mitigation and Countermeasures

Organizations should immediately remove all QuickFox Windows versions between v3.51.0 and v3.59.5, as these are confirmed to be trojanized. Network and endpoint security controls must be updated to block all identified indicators of compromise, including malicious domains (cdns3[.]51quickfox[.]cn, www[.]icloud-cdn[.]net, www[.]google-apis[.]net, www[.]techcheck1[.]com, www[.]yahoo-cdn[.]it[.]com, www[.]wangmeng[.]xyz, www[.]wangmengsb[.]com, www[.]wangmeng66[.]top), C2 IP addresses (such as 47.238.64.56, 47.239.93.49, 47.239.4.179, 47.88.21.252, 47.238.240.219, 154.223.75.206, 154.223.58.64, 45.158.180.250, 154.223.58.142, 38.60.142.56), and file hashes (2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C, 795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9, DC666E9C148BBCA5E21D8C9A97143575C075F53360F135E0191AED9E8278D396). Security teams should search for the presence of %APPDATA%\Local\Temp\quickfox\updated\Microsoft.ServiceHosting.Tools.dll and related files on endpoints, and monitor for suspicious outbound connections to FDMTP C2 infrastructure on ports 20800–20816. If infection is detected, the affected host should be immediately isolated and subjected to comprehensive forensic analysis to determine the extent of compromise and lateral movement.

Organizations are strongly advised to review their third-party software supply chain risk management practices, ensure robust endpoint detection and response (EDR) coverage, and educate users about the risks of downloading software from unofficial sources. Regularly updating software inventories and validating the integrity of installed applications can further reduce exposure to supply chain attacks.

References

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify and address vulnerabilities introduced by third-party software and services. For more information or to discuss how Rescana can help secure your organization’s digital ecosystem, we are happy to answer questions at info@rescana.com.