Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

0
Medium
Published: 08/05/2026 (08/05/2026, 08:30:10 UTC)
Source: AlienVault OTX General

Description

A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain

Affected software

Affected versions
>=3.0.51.0 <=3.59.5

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 11:29:27 UTC

Technical Analysis

A supply chain attack compromised the QuickFox VPN application, primarily used by Chinese users, by trojanizing Windows installers from versions 3.0.51.0 through 3.59.5. The compromised installers deployed malicious JavaScript through modified Electron renderer HTML files, which fingerprinted victim endpoints using process-based guardrails to identify specific applications such as administrative tools, cryptocurrency wallets, and Chinese translation software, while excluding Steam users. Successfully profiled victims were implanted with the FDMTP malware via DLL sideloading techniques leveraging legitimate Microsoft Azure binaries. The attack infrastructure includes multiple staging domains masquerading as legitimate services and shows active development. QuickFox removed the malicious components starting with version 3.59.6 after responsible disclosure. There are technical overlaps with the Twill Typhoon group, though attribution is not confirmed.

Potential Impact

The attack enabled targeted deployment of the FDMTP implant to selected victims through a trusted software supply chain, potentially compromising user systems with malware capable of evading detection by fingerprinting and selective targeting. The use of DLL sideloading with legitimate Microsoft Azure binaries increases stealth and persistence. Users running affected QuickFox versions risk infection and subsequent compromise. The removal of malicious components in version 3.59.6 mitigates the threat for updated users.

Defensive Guidance

Users should update QuickFox VPN to version 3.59.6 or later, where malicious components have been removed following responsible disclosure. Avoid using affected versions (3.0.51.0 through 3.59.5). Monitor vendor advisories for any further updates or guidance. No additional mitigation steps are specified by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant"]
Adversary
null
Pulse Id
6a72f492ee9dc3fc24d86c17
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainjiejie.net
domainwww.icloud-cdn.net
domaincdns3.51quickfox.cn
domain51quickfox.cn
domaincdns3.51quickfox.com
domainplugin.room.run
domainwww.google-apis.net
domainwww.techcheck1.com
domainwww.wangmeng.xyz
domainwww.wangmeng66.top
domainwww.wangmengsb.com

Ip

ValueDescriptionCopy
ip154.223.58.142
ip47.76.92.73
ip202.181.25.71
ip123.254.106.148
ip103.231.15.135
ip103.231.15.219
ip103.231.15.248
ip103.246.244.20
ip123.254.105.38
ip154.223.24.158
ip154.223.54.159
ip154.223.58.64
ip154.223.75.206
ip170.33.128.5
ip202.181.25.73
ip38.60.142.56
ip43.240.12.34
ip43.240.12.35
ip45.125.15.100
ip45.125.15.104
ip45.125.15.111
ip45.125.15.114
ip45.125.15.115
ip45.125.35.225
ip45.125.35.226
ip45.125.35.227
ip45.125.35.229
ip45.125.35.230
ip45.125.35.231
ip45.125.35.233
ip45.125.35.234
ip45.125.35.235
ip45.125.35.236
ip45.158.180.250
ip47.238.240.219
ip47.238.64.56
ip47.239.4.179
ip47.239.93.49
ip47.83.122.51
ip47.86.14.22
ip47.88.21.252

Hash

ValueDescriptionCopy
hash03fd832b81dd54d2bf5f610a8ff27856
hash19e760ee849eb7c1f100f2b7010a763d
hash1f3031167f94b166cc7b69376a01c124
hash2dd8681dcd218c88d1c78dfe939ec92b
hash2ffdcfb7157511789228988e26d06fd6
hash30d59c3d4916aa5fb24050c6aae7f8e4
hash3b79d95f7f7b58c401a3bc79f94ebb52
hash5e4ed6abbf555e5a542e3d4308ccd7bf
hash5f3daf7417dd666213168eb6c7453cc7
hashb1d344c9a1525373be6a3980fa85a603
hashe0a92209dd62dae8460d934dc6b7ddd7
hash11a6df1e15663ae89f59a9e598ae8987f42a632b
hash173dd4190740b96f6f733c801b6428ed4b52b607
hash2cc0425a90a39ac4eedadd59caaafad5b50f8420
hash3449a349b6c8045b16df4f88d58c65c2bdf891bb
hash39504cead410056878962053f8d027e9f299cd10
hash7ab7ffe4c233a4f2440f0fdeb2e117c788792281
hasha195810c41f401c4b48cb557cf8ce60c2d807025
hashb194a997c9a653134bdb1f2d0c3137dcdacb54d5
hashb370b674ce877b9c0a7708c7834aeb7eda983564
hashc41b4e11e6a9e3b53da1f92b213de9f65a825c92
hashe90d2730f3354ff1adf334b03c95eac3207d47b9
hash2b6cdafdfe427a3de1a94a8a2ca1f09fc4c8f90e4f59089fd9b35b73185ed01c
hash3bd3b300f3278520819a06d0cb1f0eadbf946dbbc11352538246ff075eb427f1
hash5cbb64375636e83b5f17d6083633cecc02e2a5f4168cd7cca5cdee36ccca9b38
hash6634339b813e6105b5138de6ab67b016b8dfbf49233c29de9bab3207e8b50d24
hash6932a20ac61fd3f93d7cfee414f6f46834068ac7c9ca011b054a6a10dc56b3d1
hash7462ce2595119c928cf516ec33148dc2a39dd9f71636a5c849c7ed93b7c5ca06
hash795594ad5e6f2868cc4d8ed12dabf4f3999a1477c6b250527c5ede9a98528fb9
hasha53d756f28457b1c4a239c91cdec8ed7b7da67a93e332e6df9621cbef8417474
hasha5d36edc34fe54b2092349f877daf560a98f5fea635d1ac4a110b3518102ef96
hashd9db5cbc193ddaf4c0a265804fdef70c32451daaf2974fa9adf52ce1defac5f7
hashdc666e9c148bbca5e21d8c9a97143575c075f53360f135e0191aed9e8278d396

Url

ValueDescriptionCopy
urlhttp://cdns3.51quickfox.cn/2025090411/update.zip
urlhttp://cdns3.51quickfox.cn/script/firebase-analytics-compat.js
urlhttp://cdns3.51quickfox.cn/script/firebase-app-compat.js
urlhttp://www.google-apis.net/dfsvc.exe
urlhttp://www.google-apis.net/dfsvc.exe.config
urlhttp://www.google-apis.net/wangmeng.dll
urlhttp://www.icloud-cdn.net/Client.dll
urlhttp://www.icloud-cdn.net/GetSlaver
urlhttp://www.icloud-cdn.net/checksum.bin
urlhttp://www.icloud-cdn.net/dnscfg.dll
urlhttp://www.icloud-cdn.net/vshost.exe
urlhttp://www.icloud-cdn.net:8080/GetCluster
urlhttp://www.icloud-cdn.net:8080/GetSlaver
urlhttp://www.techcheck1.com/GetClusterNodes
urlhttp://www.techcheck1.com/GetPeers
urlhttp://www.techcheck1.com/Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll
urlhttp://www.techcheck1.com/config.etl
urlhttp://www.techcheck1.com/dfsvc.exe.config
urlhttp://www.techcheck1.com/vshost.exe
urlhttp://www.techcheck1.com/wangmeng.dll
urlhttp://www.wangmeng.xyz/GetAgents
urlhttp://www.wangmeng.xyz/GetEndpoints
urlhttp://www.wangmeng.xyz/GetGateways
urlhttp://www.wangmeng.xyz/GetInstances
urlhttp://www.wangmeng.xyz/GetMachines
urlhttp://www.wangmeng.xyz/GetMembers
urlhttp://www.wangmeng.xyz/GetNodes
urlhttp://www.wangmeng.xyz/GetPeers
urlhttp://www.wangmeng.xyz/GetReplicas
urlhttp://www.wangmeng.xyz/GetRoutes
urlhttp://www.wangmeng.xyz/GetServers
urlhttp://www.wangmeng.xyz/GetTargets
urlhttp://www.wangmeng.xyz/GetVips
urlhttp://www.wangmeng.xyz/GetWorkers
urlhttp://www.wangmeng66.top/GetAddresse
urlhttp://www.wangmeng66.top/GetAddresses
urlhttp://www.wangmeng66.top/GetEndpoints
urlhttp://www.wangmeng66.top/GetHosts
urlhttp://www.wangmeng66.top/GetInstances
urlhttp://www.wangmeng66.top/GetMachines
urlhttp://www.wangmeng66.top/GetPeers
urlhttp://www.wangmeng66.top/GetProxies
urlhttp://www.wangmeng66.top/GetReplicas
urlhttp://www.wangmeng66.top/GetResources
urlhttp://www.wangmeng66.top/GetRoutes
urlhttp://www.wangmeng66.top/GetServers
urlhttp://www.wangmeng66.top/GetTargets
urlhttp://www.wangmeng66.top/GetWorkers
urlhttp://www.wangmengsb.com/GetAddresses
urlhttp://www.wangmengsb.com/GetAgents
urlhttp://www.wangmengsb.com/GetBackends
urlhttp://www.wangmengsb.com/GetEndpoints
urlhttp://www.wangmengsb.com/GetHosts
urlhttp://www.wangmengsb.com/GetIps
urlhttp://www.wangmengsb.com/GetNodes
urlhttp://www.wangmengsb.com/GetPeers
urlhttp://www.wangmengsb.com/GetReplicas
urlhttp://www.wangmengsb.com/GetRoutes
urlhttp://www.wangmengsb.com/GetServers
urlhttp://www.wangmengsb.com/GetVips
urlhttp://www.wangmengsb.com/GetWorkers

Threat ID: 6a72fab9bf8831d53992fde9

Added to database: 08/05/2026, 08:56:25 UTC

Last enriched: 08/05/2026, 11:29:27 UTC

Last updated: 08/05/2026, 18:58:24 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses