FortiGuard Labs Incident Response team documents a supply chain attack targeting QuickFox, a Windows VPN/proxy application popular among Chinese-speaking users. Attackers trojanized the QuickFox installer by modifying an embedded index.html to load a malicious JavaScript loader from a spoofed domain. This loader deploys the FDMTP implant through DLL sideloading techniques using legitimate binaries. The report details two generations of the implant, multiple staging and registration domains masquerading as iCloud, Google, and Yahoo CDNs, and an extensive list of indicators of compromise including domains, URLs, and IP addresses associated with the FDMTP cluster infrastructure.
Table of contents
Infection ProcessInfection Chain Technical AnalysisUnpacking the FDMTP ImplantVendor Engagement and ResponseAttributionConclusionFortinet ProtectionsMITRE ATT&CK MappingIndicators of Compromise319 Impressions