Threat reportSupply ChainTL-2026-1864

QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator

mediumACTIVE

QuickFox Supply Chain Attack Deploys FDMTP Implant via (TL-2026-1864), also tracked as QuickFox FDMTP Campaign, is a medium-severity supply-chain compromise, first published 2026-08-04 and last reviewed 2026-10-01. It is attributed to Mustang Panda (China) with medium confidence, affects QuickFox QuickFox Windows Desktop Application, maps to 24 MITRE ATT&CK techniques (T1016, T1027, T1033), and is covered by 9 detection rules and 36 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1Mustang Panda
Detection rules
9SPL · KQL · Sigma
IOCs
36Indicators of compromise

Key facts for TL-2026-1864

Threat ID
TL-2026-1864
Also known as
QuickFox FDMTP Campaign, Operation TouchSocket
Severity
MEDIUM
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Mustang Panda
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
technology, finance, education, government administration, cryptocurrency
Target regions
East Asia, Southeast Asia, Asia-Pacific, North America, Europe, Oceania
Detection rules
9
Indicators of compromise
36
Updates
2026-10-01 · revalidated 1× · latest source

Malware and tooling in QuickFox Supply Chain Attack Deploys FDMTP Implant via

Malware and tooling: FDMTP

How QuickFox Supply Chain Attack Deploys FDMTP Implant via works

FortiGuard Labs reports a supply chain compromise of the QuickFox VPN proxy and game accelerator (targeting Chinese users abroad) where trojanized versions of the Windows installer deliver a multi-stage JavaScript loader that downloads and installs the FDMTP (TouchSocket Duplex Message Transport Protocol) implant. Active since at least August 2025 with infrastructure still live at publication. Two loader generations observed, with process-based guardrails targeting corporate/developer/crypto/translation environments. Infrastructure and code overlap strongly with Darktrace-reported Twill Typhoon/Mustang Panda campaigns.

QuickFox is a 'return-to-China accelerator' VPN and game acceleration service used by overseas Chinese, international students, and business travelers to access Chinese-licensed content, games, and websites from abroad. Between approximately July 2025 and August 2025, the official QuickFox Windows installer (versions v3.51.0 through v3.59.5) was trojanized with two lines of malicious JavaScript injected into the Electron renderer HTML file at the path <executable>/<version>.7z/resources/app.asar/candy/core/service/index.html.

Upon execution, the trojanized QuickFox installer downloads two JavaScript files from the typosquatted domain cdns3[.]51quickfox[.]cn: a legitimate Firebase decoy (firebase-analytics-compat.js) and a heavily obfuscated malicious loader (firebase-app-compat.js). The malicious loader employs a custom obfuscation scheme with ten parallel layers of base91 decryption using distinct 91-character alphabets and flow obfuscation via nested switch statements.

The loader performs endpoint fingerprinting: it verifies the system is Windows, checks a file-based mutex at %APPDATA%\Local\Temp\quickfox\updated\data.dat (1-byte file indicating prior infection), and enumerates running processes. Critically, the loader exits if steam.exe (Steam gaming platform) is found, indicating a guardrail to avoid gaming PCs and target corporate/work environments. The loader scans for 26 other target process names associated with corporate/developer tools (SSH clients like Xshell, FinalShell, MobaXterm; IDEs like IntelliJ IDEA, VS Code, Sublime Text; database tools like Navicat, DBeaver), cryptocurrency wallets (Exodus, Binance Desktop, Ledger Live, Trezor Suite), messaging platforms (Telegram, SafeW), and Chinese translation/cross-border e-commerce software.

If the guardrail checks pass, the loader downloads update.zip from the typosquat domain to %TEMP%\quickfox\update.zip. The archive is extracted to %APPDATA%\Local\Temp\quickfox\updated\, containing csmonitor.exe (a legitimate Microsoft Azure Compute and Storage Emulator binary used for DLL sideloading) and the malicious Microsoft.ServiceHosting.Tools.dll.

Two generations of the payload have been observed:

Generation 1 (circa September 2025): The malicious DLL contains the FDMTP payload as an embedded byte array within a .NET assembly. The embedded Client.dll is instantiated via the DevStore class as a new thread within the csmonitor.exe process. SHA256: 2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C.

Generation 2 (circa May 2026): The malicious DLL is obfuscated using the JieJie .NET Protector tool and decrypts a separate update.bin file via AES-128-ECB using the hardcoded key POt_L[Bsh0=+@0a. This decryption key matches prior Darktrace reporting on FDMTP campaigns attributed to Twill Typhoon. SHA256: 795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9.

The FDMTP implant (version 3.2.5.1) is a .NET backdoor built on the TouchSocket DMTP (Duplex Message Transport Protocol) networking library. It contains 15 compressed modules in its resources section, with the main orchestration module being Client.FDMTPFrame.dll. On execution, it performs C2 registration via an HTTP GET request to /GetCluster?protocol=DotNet-TcpFDMTP&tag=<campaign> on the staging domain (observed: www[.]icloud-cdn[.]net), receiving a Base64-encoded, gzip-compressed list of IP:port endpoints for subsequent FDMTP communication on ports 20800-20816.

The implant collects extensive system information including window titles, installed antivirus products, .NET Framework version, network configuration, MAC address, OS version, installation date, username, and process lists. It supports a modular plugin architecture with observed plugins for scheduled task persistence (Persist.WpTask.dll), registry persistence (Persist.registry.dll), COM hijacking for framework persistence (Persist.extra.dll), and remote file/process manipulation (Assist.dll). Plugin executables are stored compressed under the registry key HKCU\SOFTWARE\Microsoft\IME\{HWID}.

FortiGuard Labs reports that the infrastructure was still active at the time of publication (August 4, 2026). Multiple staging domains masquerading as CDN infrastructure for well-known platforms were observed, including yahoo-cdn[.]it[.]com, google-apis[.]net, icloud-cdn[.]net, and multiple wangmeng-prefixed domains. Both FortiGuard and Darktrace note significant technical crossover with Twill Typhoon (Mustang Panda/TA416), a China-nexus espionage APT group, based on shared DLL sideloading techniques, identical FDMTP decryption keys, overlapping C2 infrastructure, and matching code structure. However, neither firm confidently attributes this specific QuickFox campaign to the actor.

The targeting assessment suggests opportunistic infection of QuickFox's user base (primarily Chinese nationals abroad) as an initial foothold, with the process guardrails and extensive data collection enabling server-side victim selection for second-stage intrusions targeting corporate, development, and cryptocurrency environments.

MITRE ATT&CK techniques used in TL-2026-1864

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1620 Reflective Code Loading

Persistence

T1053 Scheduled Task/Job; T1112 Modify Registry; T1546 Event Triggered Execution

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Initial Access

T1195 Supply Chain Compromise

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Affected products and versions in QuickFox Supply Chain Attack Deploys FDMTP Implant via

  • QuickFox — QuickFox Windows Desktop Application
    Vulnerable versions: 3.51.0; 3.55.6; 3.59.5
    Fixed in: 3.59.6
  • QuickFox — QuickFox macOS Desktop Application
    Vulnerable versions: concurrent versions
    Fixed in: 3.59.6

Remediation for QuickFox Supply Chain Attack Deploys FDMTP Implant via

Patches

  • Upgrade QuickFox Windows desktop application to v3.59.6 or later

Immediate actions

  • Update QuickFox to v3.59.6 or later on all Windows systems
  • Block network traffic to cdns3[.]51quickfox[.]cn and all associated C2 staging domains
  • Scan systems for %APPDATA%\Local\Temp\quickfox\ directory and remove if present
  • Block all C2 cluster IPs at network perimeter

Workarounds

  • Remove QuickFox if not operationally required
  • Restrict execution of csmonitor.exe outside of Azure development environments
  • Enable ASR rules to block DLL sideloading

Longer-term hardening

  • Monitor for DLL sideloading via legitimate Microsoft binaries (csmonitor.exe, dfsvc.exe, vshost.exe, biz_render.exe)
  • Implement application whitelisting for sensitive endpoints
  • Monitor Electron app child processes for anomalous command execution
  • Deploy behavioral detection rules for the FDMTP execution sequence (legit binary -> .config -> malicious DLL -> C2 registration)

Weaknesses (CWE) in QuickFox Supply Chain Attack Deploys FDMTP Implant via

CWE-494, CWE-1104, CWE-506

Timeline of QuickFox Supply Chain Attack Deploys FDMTP Implant via

  • Typosquat domain cdns3[.]51quickfox[.]cn registered via Web Commerce Communications Ltd (Malaysia) under registrant name 'Lin Tianjun', impersonating the legitimate QuickFox CDN domain 51quickfox[.]com (registered 2021-06-24 via GoDaddy). Certificate issued same day via Google Trust Services.
  • Trojanized components first introduced into the official QuickFox Windows installer. Earliest affected version identified: v3.0.51.0. Two lines of JavaScript injected into the Electron renderer HTML file at the path <executable>/<version>.7z/resources/app.asar/candy/core/service/index.html.
  • Latest confirmed injection window closure. All QuickFox Windows builds between this date and 2025-07-25 (v3.51.0 through v3.59.5) contain trojanized components.
  • Generation 1 FDMTP payload first observed. Malicious Microsoft.ServiceHosting.Tools.dll contains embedded FDMTP Client.dll as a byte array. Delivery via csmonitor.exe DLL sideloading. AV detection signature: MSIL/Agent.BB52!tr.
  • www[.]icloud-cdn[.]net infrastructure becomes active, serving /GetSlaver, /checksum.bin, and /GetCluster endpoints for FDMTP C2 registration. Activity continues through June 2026.
  • www[.]wangmeng[.]xyz infrastructure active with extensive API surface including /GetGateways, /GetVips, /GetPeers, /GetNodes, /GetTargets, /GetReplicas, /GetServers, /GetRoutes, /GetAgents, /GetMachines, /GetEndpoints, /GetWorkers, /GetInstances. Activity continues through June 2026.
  • www[.]google-apis[.]net infrastructure observed serving /dfsvc.exe, /dfsvc.exe.config, and /wangmeng.dll for alternative DLL sideloading paths.
  • www[.]yahoo-cdn[.]it[.]com infrastructure becomes active, serving /dfsvc.exe.config, /dnscfg.dll, /vshost.exe, /GetCluster, /dfsvc.exe, /Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll, and /config.etl. Activity continues through June 2026. Multiple cluster IPs assigned including 47[.]238[.]64[.]56.
  • Generation 2 FDMTP payload observed. Loader obfuscated with JieJie .NET Protector. Payload delivered as AES-128-ECB encrypted update.bin decrypted with key POt_L[Bsh0=+@0a. (matching prior Darktrace reporting on Twill Typhoon campaigns). AV detection signature: MSIL/Agent.7856!tr, Data/Agent.D7BF!tr.
  • Additional wangmeng-prefixed domains www[.]wangmengsb[.]com and www[.]wangmeng66[.]top become active, hosting extensive /GetEndpoints, /GetNodes, /GetBackends, /GetIps, /GetWorkers, /GetRoutes, /GetAddresses endpoint collections.
  • Latest observed C2 infrastructure activity. Multiple staging domains and cluster IPs still live at time of FortiGuard publication. Domain www[.]techcheck1[.]com also active with /config.etl, /wangmeng.dll, /GetPeers, /GetClusterNodes endpoints.
  • QuickFox releases v3.59.6 removing trojanized components from Windows and macOS installers following notification from Fortinet. Older versions 3.51.0-3.59.5 remain compromised.
  • FortiGuard Labs publishes comprehensive technical analysis of the QuickFox supply chain attack and FDMTP implant, noting infrastructure still live at publication.
  • The Hacker News covers the Fortinet report; press cites tactical overlap with Mustang Panda, while Fortinet itself does not attribute the campaign.

Update history for TL-2026-1864

  • 2026-10-01 — QuickFox VPN Supply Chain Attack Used to Deploy FDMTP Implant: What changed No severity, exploitability, status or attribution change. The additions are corroborating detail from the same Fortinet analysis. New indicators (5) 2 additional FDMTP cluster IPs (47.88.21.252, 47.238.240.219), the Gen1 updat

Sources cited for QuickFox Supply Chain Attack Deploys FDMTP Implant via

Detection coverage for TL-2026-1864

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1864 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
36 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats