Skip to content
Threat Feed
high advisory

QuickFox Supply Chain Attack and FDMTP Implant Deployment

Threat actors compromised QuickFox software supply chain to distribute trojanized Windows installers, resulting in the installation of a custom FDMTP implant for persistent access.

The FortiGuard Labs Incident Response team has identified a sophisticated supply chain attack targeting users of the QuickFox application. Attackers successfully trojanized legitimate Windows installers, allowing them to gain initial access to victim environments through a trusted delivery mechanism. Upon execution of the compromised installer, the attack proceeds to deploy a custom, evolving malware implant identified as FDMTP. This implant is designed for persistent access and modular functionality, enabling the operators to conduct targeted operations within compromised networks. The selective nature of the targeting suggests a focused campaign rather than indiscriminate mass distribution, which increases the risk to enterprise environments that rely on this software for network optimization. Defenders should prioritize auditing the integrity of software deployment pipelines and monitoring for unauthorized persistence mechanisms associated with this implant.

Impact

The impact of this campaign involves potential unauthorized access to target systems, potential exfiltration of sensitive information, and long-term persistence in affected environments. The specific targeting indicates that selected organizations are at higher risk of compromise. Organizations utilizing QuickFox should conduct immediate forensic reviews of endpoints where the software is deployed to detect unauthorized modification or presence of the FDMTP implant.

Recommendation

  • Perform a baseline integrity audit of the QuickFox installation files across all endpoints to ensure they match legitimate vendor signatures.
  • Monitor for unexpected processes spawned by software installers or updater binaries.
  • Review endpoint telemetry for suspicious persistence mechanisms, specifically looking for anomalous registry modifications or scheduled tasks created shortly after software installation events.
  • Isolate systems where QuickFox was updated or reinstalled during the identified campaign window for forensic analysis.

Immediate actions

Integrity audit of installed QuickFox binaries and verification against known good hashes

IT Operations 48h

Threat Hunt

Investigation of unauthorized persistence mechanisms (Registry keys/Scheduled Tasks) on hosts running QuickFox

T1547 high high confidence hunt now

Data: Process creation events, Registry modifications