QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
Fortinet, Tuesday, August 4th, 2026
FortiGuard Labs analyzes a QuickFox VPN supply chain attack delivering the FDMTP implant selectively.
The FortiGuard Labs Incident Response team has analyzed a supply chain attack against the QuickFox VPN client.
Attackers distributed trojanized Windows installers through the legitimate distribution channel.
They used selective targeting to deliver the malicious payload only to victims of interest, limiting exposure of the operation. The delivered implant, tracked as FDMTP, has continued to evolve across observed samples.