Security News

Cybersecurity news aggregator

⚔️
MEDIUM Attacks FortiGuard Outbreak Alerts

QuickFox Supply Chain Attack

  • What: A supply chain attack targeting QuickFox, a Windows VPN application, has been discovered.
  • Impact: Users of QuickFox, particularly overseas Chinese users, may be at risk.
Read Full Article →

Outbreak Alert QuickFox Supply Chain Attack Released: Aug 06, 2026 Updated: Aug 07, 2026 Download PDF » Share QuickFox Supply Chain Attack Attack Tags Medium Severity Share Subscribe Overview Analysis Solutions Threat Intelligence References Subscribe Overview Analysis Solutions Threat Intelligence References Supply Chain Compromise / Backdoor Deployment FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access. The campaign has reportedly been active since August 2025 before being publicly disclosed in August 2026. Learn More » Background Unlike opportunistic malware campaigns, the trojanized QuickFox installer fingerprints each system and deploys the FDMTP backdoor only when attacker-defined criteria are met, indicating a highly selective espionage operation rather than indiscriminate malware distribution. Because the incident resulted from a compromised software supply chain rather than a vulnerability in the application itself, no CVE has been assigned. QuickFox is a network acceleration application that combines VPN and proxy technologies to help overseas Chinese users securely access online services hosted in mainland China. Its primary user base includes expatriates, international students, business travelers, and organizations requiring access to China-based applications and services. Based on QuickFox's intended user base, the United States, Canada, Australia, the United Kingdom, and Japan are likely among the regions with the highest exposure. However, these represent expected deployment locations rather than confirmed victim telemetry, as no country-specific compromise data has been published. Latest Development Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered. Publicly confirmed affected versions are 3.0.51.0–3.59.5, with 3.59.6 serving as the clean release. August 04, 2026: FortiGuard Labs publicly discloses campaign. https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant August 01, 2026: QuickFox releases version 3.59.6 removing malicious components. FortiGuard Cybersecurity Framework Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services. PROTECT AV AV (Pre-filter) Web & DNS Filter DETECT IOC RESPOND Automated Response Assisted Response Services RECOVER NOC/SOC Training End-User Training IDENTIFY Attack Surface Hardening AV Detects known malware related to the Outbreak FortiADC DB 93.07679 FortiCASB DB 93.07679 FortiCWP DB 93.07679 FortiClient DB 93.07679 FortiGate DB 93.07679 FortiMail DB 93.07679 FortiProxy DB 93.07679 FortiSASE DB 93.07679 FortiWeb DB 93.07679 AV (Pre-filter) Detects known malware related to the Outbreak FortiEDR DB 93.07679 FortiNDR DB 93.07679 FortiSandbox DB 93.07679 Web & DNS Filter Blocks known malicious infrastructure used by the campaign. FortiClient FortiGate FortiMail FortiProxy FortiSASE IOC FortiAnalyzer FortiCloud SOCaaS FortiSIEM FortiSOAR Automated Response Services that can automaticlly respond to this outbreak. FortiXDR Assisted Response Services Experts to assist you with analysis, containment and response activities. Incident Response NOC/SOC Training Train your network and security professionals and optimize your incident response to stay on top of the cyberattacks. NSE Training Response Readiness End-User Training Raise security awareness to your employees that are continuously being targeted by phishing, drive-by download and other forms of cyberattacks. Security Awareness & Training Attack Surface Hardening Check Security Fabric devices to build actionable configuration recommendations and key indicators. Security Rating Threat Intelligence Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities. ✖ References Sources of information in support and relation to this Outbreak and vendor. FortiGuard Labs Threat Research Learn More » About FortiGuard Outbreak Alerts Learn More »

Share this article