A supply chain attack on the QuickFox VPN/game accelerator application trojanized versions 3.51.0 through 3.59.5 by injecting malicious JavaScript into an Electron renderer HTML file. The JavaScript downloaded an obfuscated loader from a typosquatting domain (cdns3.51quickfox.cn) that enforced execution guardrails before deploying an FDMTP implant via DLL sideloading using a legitimate Microsoft binary (csmonitor.exe). The FDMTP implant established C2 via a custom protocol on ports 20800-20816, collected host information, and supported remote plugin deployment through registry-based storage. Infrastructure remains active and shares technical overlap with the Twill Typhoon threat actor.
FDMTP Implant
1 post
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant