QuickFox Supply-Chain Attack Deployed FDMTP Implant on Windows Systems

Summary
FortiGuard Labs detailed a QuickFox supply-chain compromise that delivered an FDMTP implant to selected Windows users. QuickFox removed the malicious components from its Windows installer in version 3.59.6 after Fortinet's notification.
Key points
- Trojanized Windows installers modified an Electron HTML file to run JavaScript loaders that downloaded and installed the FDMTP implant.
- Fortinet identified affected Windows versions from 3.51.0 through 3.59.5; QuickFox removed the malicious components in version 3.59.6.
- The malware used process checks to select targets, stopping if Steam was running and requiring at least one process from a list of business, developer, translation, or crypto applications.
- The implant used DLL sideloading through the legitimate csmonitor.exe binary and communicated with FDMTP command-and-control infrastructure.
- It collected host and process information and supported remotely delivered plugins; Fortinet observed little post-install activity beyond initial enumeration.
- Fortinet found technical and infrastructure overlaps with a campaign previously reported by Darktrace, but did not confidently attribute the QuickFox campaign to a specific actor.
Article Details
- Attack Vectors
- A trojanized application installer included two added JavaScript lines in an embedded Electron renderer HTML file, causing initialization to download and execute a loader from masquerading infrastructure.
- The initial loader restricted execution to Windows, stopped when steam.exe was running, and downloaded the next stage only when at least one of 26 selected application processes was present.
- Downloaded archives combined a legitimate executable with a malicious DLL for sideloading. The first loader generation embedded the implant; the second decrypted an adjacent encrypted payload file.
- The implant registered with a staging server, retrieved cluster addresses, and established a separate socket-based command channel.
- Server-delivered plugins were stored in the registry, decompressed and loaded on command. An analyzed plugin could download additional executable files for subsequent execution.
- Defensive Notes
- The source reports removal of malicious Windows installer components in version 3.59.6, first observed on 2026-06-29. Other passages instead cite 3.55.6 as the remediation boundary; the article therefore contains inconsistent version guidance.
- Available historical installers were not an exhaustive set. Modified HTML also appeared in some Mac builds, but Windows-only execution checks prevented infection progression there; corresponding initial infection behavior was not observed in iOS or Android builds.
- Evaluate process lineage through the application's Electron child process. Numerous application child processes are not inherently malicious, whereas the loader's repeated cmd.exe invocations warrant contextual investigation.
- Obfuscated JavaScript alone is not anomalous in an Electron application; assess its download behavior, execution checks, and infrastructure relationships.
- Fortinet reports antivirus signatures, malicious URL ratings, and IP reputation protections associated with this investigation. The source states that supported products with current protections protect customers.
- FortiGuard Labs observed no significant post-exploitation activity beyond the reported enumeration and plugin functionality, limiting confidence in attribution and ultimate targeting.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 51quickfox[.]cn | Unofficial lookalike domain associated with the malicious QuickFox delivery host. |
| DOMAIN | cdns3[.]51quickfox[.]cn | Malicious QuickFox lookalike host delivering initial scripts and payload archives. |
| DOMAIN | www[.]google-apis[.]net | FDMTP staging and registration domain that also hosts implant components. |
| DOMAIN | www[.]icloud-cdn[.]net | FDMTP staging and registration domain providing cluster connection details. |
| DOMAIN | www[.]techcheck1[.]com | FDMTP staging and registration domain that also hosts implant components. |
| DOMAIN | www[.]wangmeng[.]xyz | FDMTP staging and registration domain providing cluster connection details. |
| DOMAIN | www[.]wangmeng66[.]top | FDMTP staging and registration domain providing cluster connection details. |
| DOMAIN | www[.]wangmengsb[.]com | FDMTP staging and registration domain providing cluster connection details. |
| DOMAIN | www[.]yahoo-cdn[.]it[.]com | FDMTP staging, registration, and payload infrastructure. |
| IPV4 | 103[.]231[.]15[.]135 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 103[.]231[.]15[.]219 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 103[.]231[.]15[.]248 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 103[.]246[.]244[.]13 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 103[.]246[.]244[.]20 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 123[.]254[.]105[.]38 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 123[.]254[.]106[.]148 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 154[.]223[.]24[.]158 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 154[.]223[.]54[.]159 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 154[.]223[.]58[.]142 | FDMTP C2 cluster node. |
| IPV4 | 154[.]223[.]58[.]64 | FDMTP C2 cluster node. |
| IPV4 | 154[.]223[.]75[.]206 | FDMTP C2 cluster node. |
| IPV4 | 170[.]33[.]128[.]5 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 202[.]181[.]25[.]71 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 202[.]181[.]25[.]73 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 38[.]60[.]142[.]56 | FDMTP C2 cluster node shared by identified staging domains. |
| IPV4 | 43[.]240[.]12[.]34 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 43[.]240[.]12[.]35 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]15[.]100 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]15[.]104 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]15[.]111 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]15[.]114 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]15[.]115 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]225 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]226 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]227 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]229 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]230 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]231 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]232 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]233 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]234 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]235 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]125[.]35[.]236 | Address identified for the FDMTP staging host www[.]wangmeng66[.]top. |
| IPV4 | 45[.]158[.]180[.]250 | FDMTP C2 cluster node. |
| IPV4 | 47[.]238[.]240[.]219 | FDMTP C2 cluster node. |
| IPV4 | 47[.]238[.]64[.]56 | FDMTP C2 cluster node. |
| IPV4 | 47[.]239[.]4[.]179 | FDMTP C2 cluster node linked to multiple staging domains. |
| IPV4 | 47[.]239[.]93[.]49 | FDMTP C2 cluster node. |
| IPV4 | 47[.]76[.]92[.]73 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 47[.]83[.]122[.]51 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 47[.]86[.]14[.]22 | Address identified for the FDMTP staging host www[.]icloud-cdn[.]net. |
| IPV4 | 47[.]88[.]21[.]252 | FDMTP C2 cluster node. |
| MD5 | 03fd832b81dd54d2bf5f610a8ff27856 | Generation 2 Microsoft.ServiceHosting.Tools.dll FDMTP loader. |
| MD5 | 19e760ee849eb7c1f100f2b7010a763d | Additional encrypted FDMTP payload sample in the host IOC table. |
| MD5 | 1f3031167f94b166cc7b69376a01c124 | config.bin FDMTP payload artifact. |
| MD5 | 2dd8681dcd218c88d1c78dfe939ec92b | Generation 2 FDMTP loader associated with config.bin. |
| MD5 | 30d59c3d4916aa5fb24050c6aae7f8e4 | update.zip archive containing the generation 1 FDMTP loader and sideloading executable. |
| MD5 | 3b79d95f7f7b58c401a3bc79f94ebb52 | Source-listed hash of the generation 1 Microsoft.ServiceHosting.Tools.dll FDMTP loader. |
| MD5 | 5e4ed6abbf555e5a542e3d4308ccd7bf | Encrypted FDMTP payload stored in update.bin. |
| MD5 | 5f3daf7417dd666213168eb6c7453cc7 | Additional campaign artifact explicitly listed in the host-based IOC table. |
| MD5 | b1d344c9a1525373be6a3980fa85a603 | Additional campaign artifact explicitly listed in the host-based IOC table. |
| MD5 | e0a92209dd62dae8460d934dc6b7ddd7 | update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable. |
| SHA1 | 11a6df1e15663ae89f59a9e598ae8987f42a632b | Additional campaign artifact explicitly listed in the host-based IOC table. |
| SHA1 | 173dd4190740b96f6f733c801b6428ed4b52b607 | Generation 1 Microsoft.ServiceHosting.Tools.dll FDMTP loader. |
| SHA1 | 2cc0425a90a39ac4eedadd59caaafad5b50f8420 | update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable. |
| SHA1 | 3449a349b6c8045b16df4f88d58c65c2bdf891bb | Additional encrypted FDMTP payload sample in the host IOC table. |
| SHA1 | 7ab7ffe4c233a4f2440f0fdeb2e117c788792281 | Generation 2 Microsoft.ServiceHosting.Tools.dll FDMTP loader. |
| SHA1 | a195810c41f401c4b48cb557cf8ce60c2d807025 | update.zip archive containing the generation 1 FDMTP loader and sideloading executable. |
| SHA1 | b194a997c9a653134bdb1f2d0c3137dcdacb54d5 | config.bin FDMTP payload artifact. |
| SHA1 | b370b674ce877b9c0a7708c7834aeb7eda983564 | Encrypted FDMTP payload stored in update.bin. |
| SHA1 | c41b4e11e6a9e3b53da1f92b213de9f65a825c92 | Generation 2 FDMTP loader associated with config.bin. |
| SHA1 | e90d2730f3354ff1adf334b03c95eac3207d47b9 | Additional campaign artifact explicitly listed in the host-based IOC table. |
| SHA256 | 2b6cdafdfe427a3de1a94a8a2ca1f09fc4c8f90e4f59089fd9b35b73185ed01c | Generation 1 Microsoft.ServiceHosting.Tools.dll loader with an embedded FDMTP payload. |
| SHA256 | 3bd3b300f3278520819a06d0cb1f0eadbf946dbbc11352538246ff075eb427f1 | Additional campaign artifact explicitly listed in the host-based IOC table. |
| SHA256 | 5cbb64375636e83b5f17d6083633cecc02e2a5f4168cd7cca5cdee36ccca9b38 | Additional encrypted FDMTP payload sample in the host IOC table. |
| SHA256 | 6634339b813e6105b5138de6ab67b016b8dfbf49233c29de9bab3207e8b50d24 | Generation 2 loader that decrypts and reflectively loads config.bin. |
| SHA256 | 6932a20ac61fd3f93d7cfee414f6f46834068ac7c9ca011b054a6a10dc56b3d1 | Additional campaign artifact explicitly listed in the host-based IOC table. |
| SHA256 | 7462ce2595119c928cf516ec33148dc2a39dd9f71636a5c849c7ed93b7c5ca06 | update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable. |
| SHA256 | 795594ad5e6f2868cc4d8ed12dabf4f3999a1477c6b250527c5ede9a98528fb9 | Generation 2 loader that decrypts and reflectively loads update.bin. |
| SHA256 | a53d756f28457b1c4a239c91cdec8ed7b7da67a93e332e6df9621cbef8417474 | config.bin FDMTP payload artifact. |
| SHA256 | d9db5cbc193ddaf4c0a265804fdef70c32451daaf2974fa9adf52ce1defac5f7 | update.zip archive containing the generation 1 FDMTP loader and sideloading executable. |
| SHA256 | dc666e9c148bbca5e21d8c9a97143575c075f53360f135e0191aed9e8278d396 | Encrypted update.bin payload loaded by the generation 2 FDMTP loader. |
| URL | hxxp[:]//cdns3[.]51quickfox[.]cn/2025090411/update[.]zip | Loader download URL for the archive containing the FDMTP deployment components. |
MITRE ATT&CK
T1010 · Application Window DiscoveryThe implant collects the window title of the topmost active program.T1016 · System Network Configuration DiscoveryFDMTP collects the endpoint IP address, gateway IP address, and MAC address.T1027 · Obfuscated Files or InformationThe initial JavaScript uses layered encoding and control-flow obfuscation; the second-generation .NET loader uses JieJie .NET Protector.T1033 · System Owner/User DiscoveryThe implant reports the current username to its C2 server.T1036.005 · Match Legitimate Resource Name or LocationInitial delivery infrastructure resembles legitimate QuickFox infrastructure, and the malicious JavaScript masquerades as Firebase SDK code.T1057 · Process DiscoveryThe loader checks tasklist output, and FDMTP retrieves process names and PIDs through EnumProcessByJson.T1059.003 · Windows Command ShellThe JavaScript loader invokes tasklist through cmd.exe child processes to inspect running applications.T1059.007 · JavaScriptJavaScript executed within QuickFox performs endpoint checks and downloads and launches subsequent infection components.T1071.001 · Web ProtocolsInitial downloads and implant registration use web requests to malicious delivery and staging domains.T1082 · System Information DiscoveryFDMTP collects Windows OS details, installation time, and the .NET Framework runtime version during registration.T1104 · Multi-Stage ChannelsWeb-based registration returns cluster addresses for subsequent socket-based FDMTP communications.T1105 · Ingress Tool TransferThe loader downloads update.zip, while server-delivered plugins can retrieve additional executable components.T1112 · Modify RegistryFDMTP stores compressed plugin executables under HKCU\SOFTWARE\Microsoft\IME\{Common.HostInfo.HWID} for later retrieval and execution.T1140 · Deobfuscate/Decode Files or InformationThe second-generation loader decrypts the FDMTP payload with AES-128-ECB, and implant modules and plugins are decompressed before loading.T1195.002 · Compromise Software Supply ChainThe QuickFox installer was compromised by adding downloader JavaScript to its embedded Electron renderer HTML.T1480 · Execution GuardrailsThe loader requires Windows, rejects endpoints running steam.exe, and proceeds only if a selected application process is present.T1518.001 · Security Software DiscoveryThe implant includes installed antivirus software in the host information sent to C2.T1574.001 · DLLThe article maps csmonitor.exe loading the malicious Microsoft.ServiceHosting.Tools.dll to this ID.T1620 · Reflective Code LoadingThe generation 2 loader reflectively loads the decrypted FDMTP payload, and the implant loads decompressed plugin assemblies.
People
Threat Actors
Malware
Vendors
FortinetFortinet has contacted QuickFox as part of our responsible disclosure process.Microsoft2025 – involves an ‘update.zip’ file that contains two components:‘csmonitor.exe’, a legitimate Microsoft binary ‘Windows Azure Compute and Storage Emulator’ used to sideload ‘Microsoft.ServiceHosting.Tools.dll’QuickFoxImpact Parties: QuickFox Users
Products
.NET FrameworkThis method is called when the .NET Framework can’t find a module that the client module is trying to load (i.e., when an ‘Assembly Resolve’ event is triggered).ElectronThe attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader.FortiClientFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiEDRFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiGateFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiMailFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.Microsoft Azure SDK‘Microsoft.ServiceHosting.Tools.dll’, a trojanized version of Microsoft Azure SDK that contains an FDMTP payload embedded within the file itself.Microsoft WindowsAffected Platforms: Windows EndpointsQuickFoxImpact Parties: QuickFox UsersSogou Pinyin IMEcampaign, the adversary leveraged the legitimate ‘biz_render.exe’ binary, a legitimate component of Sogou Pinyin IME, as the sideloading target, with their loader replacing ‘browser_host.dll’, whereas in our case, theSteamThe script will stop and exit if a process named ‘steam.exe’ is in the tasklist output.Windows Azure Compute and Storage Emulatorfile that contains two components:‘csmonitor.exe’, a legitimate Microsoft binary ‘Windows Azure Compute and Storage Emulator’ used to sideload ‘Microsoft.ServiceHosting.Tools.dll’