Mustang Panda Hid FDMTP Backdoor in QuickFox VPN via Supply Chain Attack
This digest was compiled by AI from multiple sources — links to the originals are below.

Chinese APT group Mustang Panda compromised QuickFox VPN through a trojanized Windows installer, deploying FDMTP backdoor to Chinese users since at least August 2025. The attackers used a fake domain (cdns3.51quickfox.cn) and JavaScript loader to fingerprint systems, evading those with Steam or lacking specific Chinese apps. QuickFox released a patched version in mid-2025, but earlier downloads may still be infected.
The Supply Chain Attack
FortiGuard Labs disclosed that since at least August 2025, QuickFox's Windows installer contained two lines of malicious JavaScript in an Electron renderer HTML file. These lines fetched and executed two payloads from cdns3.51quickfox.cn, a domain mimicking the official 51quickfox.com. The first, 'firebase-app-compat.js', was an obfuscated loader performing system checks, while the second, 'firebase-analytics-compat.js', held legitimate Firebase code as camouflage. Fortinet attributed the attack to Mustang Panda, a Chinese state-sponsored threat actor.
Evasion and Targeting
The loader confirmed a Windows OS, queried a C2 server to avoid re‑infection, and ran 'tasklist' to examine processes. Execution halted if steam.exe was present or if none of 26 specific applications (including Xshell, Navicat, SafeW, Binance, and Ledger Live) were found. Only then did the script download the FDMTP backdoor ZIP archive from the same rogue domain. Two generations of the ZIP payload have been identified since September 2025.
Cleanup and Residual Risk
After responsible disclosure, QuickFox removed the malicious code in version 3.59.6, with changes applied between July 25 and August 13, 2025. The earliest known affected version was 3.0.51.0, creating a window of vulnerable installs. Despite the fix, users who downloaded the trojanized installer before the update remain infected unless they manually clean their systems.
What's Next
QuickFox users are urged to update to version 3.59.6 or later and scan for FDMTP. It remains unclear whether Mustang Panda has shifted to alternative delivery methods or how many endpoints are still compromised.
2 sources
Mustang Panda Hid FDMTP Backdoor in QuickFox VPN via Supply Chain Attack



