Executive Summary
FortiGuard Labs identified a long-running supply chain attack active since August 2025 targeting the QuickFox application, a VPN proxy and game accelerator. The campaign, which shows technical crossovers with the threat actor Twill Typhoon, uses a trojanized Electron renderer HTML file to initiate a multi-stage infection process. The attack specifically targets Windows endpoints and employs sophisticated guardrails to ensure payloads are deployed primarily in corporate or professional environments.
The infection chain begins with a modified index.html that downloads obfuscated JavaScript to fingerprint the victim. If specific administrative, development, or translation processes are detected—and the Steam gaming platform is not running—the loader proceeds to download a second-stage ZIP file. This package utilizes DLL sideloading of a legitimate Microsoft binary (csmonitor.exe) to execute the FDMTP implant, a modular .NET malware designed for persistent access and data exfiltration.
This campaign is significant due to its use of popular utility software to bypass perimeter defenses and its specific targeting of Chinese users and professionals interacting with Chinese-native services. The active nature of the infrastructure and the evolution of the FDMTP loader demonstrate a persistent and evolving threat that requires targeted monitoring for anomalous Electron application behavior and non-standard network protocols like FDMTP.
