<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Fortiguard - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/fortiguard/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 04 Aug 2026 13:43:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/fortiguard/feed.xml" rel="self" type="application/rss+xml"/><item><title>QuickFox Supply Chain Attack and FDMTP Implant Deployment</title><link>https://feed.craftedsignal.io/briefs/2026-08-quickfox-supply-chain/</link><pubDate>Tue, 04 Aug 2026 13:43:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-quickfox-supply-chain/</guid><description>Threat actors compromised QuickFox software supply chain to distribute trojanized Windows installers, resulting in the installation of a custom FDMTP implant for persistent access.</description><content:encoded><![CDATA[<p>The FortiGuard Labs Incident Response team has identified a sophisticated supply chain attack targeting users of the QuickFox application. Attackers successfully trojanized legitimate Windows installers, allowing them to gain initial access to victim environments through a trusted delivery mechanism. Upon execution of the compromised installer, the attack proceeds to deploy a custom, evolving malware implant identified as FDMTP. This implant is designed for persistent access and modular functionality, enabling the operators to conduct targeted operations within compromised networks. The selective nature of the targeting suggests a focused campaign rather than indiscriminate mass distribution, which increases the risk to enterprise environments that rely on this software for network optimization. Defenders should prioritize auditing the integrity of software deployment pipelines and monitoring for unauthorized persistence mechanisms associated with this implant.</p>
<h2 id="impact">Impact</h2>
<p>The impact of this campaign involves potential unauthorized access to target systems, potential exfiltration of sensitive information, and long-term persistence in affected environments. The specific targeting indicates that selected organizations are at higher risk of compromise. Organizations utilizing QuickFox should conduct immediate forensic reviews of endpoints where the software is deployed to detect unauthorized modification or presence of the FDMTP implant.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform a baseline integrity audit of the QuickFox installation files across all endpoints to ensure they match legitimate vendor signatures.</li>
<li>Monitor for unexpected processes spawned by software installers or updater binaries.</li>
<li>Review endpoint telemetry for suspicious persistence mechanisms, specifically looking for anomalous registry modifications or scheduled tasks created shortly after software installation events.</li>
<li>Isolate systems where QuickFox was updated or reinstalled during the identified campaign window for forensic analysis.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain-attack</category><category>implant</category><category>windows</category><category>fortiguard</category></item></channel></rss>