QuickFox Supply-Chain Attack Deployed FDMTP Implant on Windows Systems

· Original article ↗

Summary

FortiGuard Labs detailed a QuickFox supply-chain compromise that delivered an FDMTP implant to selected Windows users. QuickFox removed the malicious components from its Windows installer in version 3.59.6 after Fortinet's notification.

Key points

  • Trojanized Windows installers modified an Electron HTML file to run JavaScript loaders that downloaded and installed the FDMTP implant.
  • Fortinet identified affected Windows versions from 3.51.0 through 3.59.5; QuickFox removed the malicious components in version 3.59.6.
  • The malware used process checks to select targets, stopping if Steam was running and requiring at least one process from a list of business, developer, translation, or crypto applications.
  • The implant used DLL sideloading through the legitimate csmonitor.exe binary and communicated with FDMTP command-and-control infrastructure.
  • It collected host and process information and supported remotely delivered plugins; Fortinet observed little post-install activity beyond initial enumeration.
  • Fortinet found technical and infrastructure overlaps with a campaign previously reported by Darktrace, but did not confidently attribute the QuickFox campaign to a specific actor.

Article Details

Attack Vectors
  • A trojanized application installer included two added JavaScript lines in an embedded Electron renderer HTML file, causing initialization to download and execute a loader from masquerading infrastructure.
  • The initial loader restricted execution to Windows, stopped when steam.exe was running, and downloaded the next stage only when at least one of 26 selected application processes was present.
  • Downloaded archives combined a legitimate executable with a malicious DLL for sideloading. The first loader generation embedded the implant; the second decrypted an adjacent encrypted payload file.
  • The implant registered with a staging server, retrieved cluster addresses, and established a separate socket-based command channel.
  • Server-delivered plugins were stored in the registry, decompressed and loaded on command. An analyzed plugin could download additional executable files for subsequent execution.
Defensive Notes
  • The source reports removal of malicious Windows installer components in version 3.59.6, first observed on 2026-06-29. Other passages instead cite 3.55.6 as the remediation boundary; the article therefore contains inconsistent version guidance.
  • Available historical installers were not an exhaustive set. Modified HTML also appeared in some Mac builds, but Windows-only execution checks prevented infection progression there; corresponding initial infection behavior was not observed in iOS or Android builds.
  • Evaluate process lineage through the application's Electron child process. Numerous application child processes are not inherently malicious, whereas the loader's repeated cmd.exe invocations warrant contextual investigation.
  • Obfuscated JavaScript alone is not anomalous in an Electron application; assess its download behavior, execution checks, and infrastructure relationships.
  • Fortinet reports antivirus signatures, malicious URL ratings, and IP reputation protections associated with this investigation. The source states that supported products with current protections protect customers.
  • FortiGuard Labs observed no significant post-exploitation activity beyond the reported enumeration and plugin functionality, limiting confidence in attribution and ultimate targeting.

Indicators of compromise

TypeIndicatorContext
DOMAIN51quickfox[.]cnUnofficial lookalike domain associated with the malicious QuickFox delivery host.
DOMAINcdns3[.]51quickfox[.]cnMalicious QuickFox lookalike host delivering initial scripts and payload archives.
DOMAINwww[.]google-apis[.]netFDMTP staging and registration domain that also hosts implant components.
DOMAINwww[.]icloud-cdn[.]netFDMTP staging and registration domain providing cluster connection details.
DOMAINwww[.]techcheck1[.]comFDMTP staging and registration domain that also hosts implant components.
DOMAINwww[.]wangmeng[.]xyzFDMTP staging and registration domain providing cluster connection details.
DOMAINwww[.]wangmeng66[.]topFDMTP staging and registration domain providing cluster connection details.
DOMAINwww[.]wangmengsb[.]comFDMTP staging and registration domain providing cluster connection details.
DOMAINwww[.]yahoo-cdn[.]it[.]comFDMTP staging, registration, and payload infrastructure.
IPV4103[.]231[.]15[.]135Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4103[.]231[.]15[.]219Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4103[.]231[.]15[.]248Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4103[.]246[.]244[.]13Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4103[.]246[.]244[.]20Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4123[.]254[.]105[.]38Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4123[.]254[.]106[.]148Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4154[.]223[.]24[.]158Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV4154[.]223[.]54[.]159Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV4154[.]223[.]58[.]142FDMTP C2 cluster node.
IPV4154[.]223[.]58[.]64FDMTP C2 cluster node.
IPV4154[.]223[.]75[.]206FDMTP C2 cluster node.
IPV4170[.]33[.]128[.]5Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV4202[.]181[.]25[.]71Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV4202[.]181[.]25[.]73Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV438[.]60[.]142[.]56FDMTP C2 cluster node shared by identified staging domains.
IPV443[.]240[.]12[.]34Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV443[.]240[.]12[.]35Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]15[.]100Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]15[.]104Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]15[.]111Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]15[.]114Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]15[.]115Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]225Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]226Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]227Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]229Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]230Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]231Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]232Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]233Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]234Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]235Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]125[.]35[.]236Address identified for the FDMTP staging host www[.]wangmeng66[.]top.
IPV445[.]158[.]180[.]250FDMTP C2 cluster node.
IPV447[.]238[.]240[.]219FDMTP C2 cluster node.
IPV447[.]238[.]64[.]56FDMTP C2 cluster node.
IPV447[.]239[.]4[.]179FDMTP C2 cluster node linked to multiple staging domains.
IPV447[.]239[.]93[.]49FDMTP C2 cluster node.
IPV447[.]76[.]92[.]73Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV447[.]83[.]122[.]51Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV447[.]86[.]14[.]22Address identified for the FDMTP staging host www[.]icloud-cdn[.]net.
IPV447[.]88[.]21[.]252FDMTP C2 cluster node.
MD503fd832b81dd54d2bf5f610a8ff27856Generation 2 Microsoft.ServiceHosting.Tools.dll FDMTP loader.
MD519e760ee849eb7c1f100f2b7010a763dAdditional encrypted FDMTP payload sample in the host IOC table.
MD51f3031167f94b166cc7b69376a01c124config.bin FDMTP payload artifact.
MD52dd8681dcd218c88d1c78dfe939ec92bGeneration 2 FDMTP loader associated with config.bin.
MD530d59c3d4916aa5fb24050c6aae7f8e4update.zip archive containing the generation 1 FDMTP loader and sideloading executable.
MD53b79d95f7f7b58c401a3bc79f94ebb52Source-listed hash of the generation 1 Microsoft.ServiceHosting.Tools.dll FDMTP loader.
MD55e4ed6abbf555e5a542e3d4308ccd7bfEncrypted FDMTP payload stored in update.bin.
MD55f3daf7417dd666213168eb6c7453cc7Additional campaign artifact explicitly listed in the host-based IOC table.
MD5b1d344c9a1525373be6a3980fa85a603Additional campaign artifact explicitly listed in the host-based IOC table.
MD5e0a92209dd62dae8460d934dc6b7ddd7update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable.
SHA111a6df1e15663ae89f59a9e598ae8987f42a632bAdditional campaign artifact explicitly listed in the host-based IOC table.
SHA1173dd4190740b96f6f733c801b6428ed4b52b607Generation 1 Microsoft.ServiceHosting.Tools.dll FDMTP loader.
SHA12cc0425a90a39ac4eedadd59caaafad5b50f8420update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable.
SHA13449a349b6c8045b16df4f88d58c65c2bdf891bbAdditional encrypted FDMTP payload sample in the host IOC table.
SHA17ab7ffe4c233a4f2440f0fdeb2e117c788792281Generation 2 Microsoft.ServiceHosting.Tools.dll FDMTP loader.
SHA1a195810c41f401c4b48cb557cf8ce60c2d807025update.zip archive containing the generation 1 FDMTP loader and sideloading executable.
SHA1b194a997c9a653134bdb1f2d0c3137dcdacb54d5config.bin FDMTP payload artifact.
SHA1b370b674ce877b9c0a7708c7834aeb7eda983564Encrypted FDMTP payload stored in update.bin.
SHA1c41b4e11e6a9e3b53da1f92b213de9f65a825c92Generation 2 FDMTP loader associated with config.bin.
SHA1e90d2730f3354ff1adf334b03c95eac3207d47b9Additional campaign artifact explicitly listed in the host-based IOC table.
SHA2562b6cdafdfe427a3de1a94a8a2ca1f09fc4c8f90e4f59089fd9b35b73185ed01cGeneration 1 Microsoft.ServiceHosting.Tools.dll loader with an embedded FDMTP payload.
SHA2563bd3b300f3278520819a06d0cb1f0eadbf946dbbc11352538246ff075eb427f1Additional campaign artifact explicitly listed in the host-based IOC table.
SHA2565cbb64375636e83b5f17d6083633cecc02e2a5f4168cd7cca5cdee36ccca9b38Additional encrypted FDMTP payload sample in the host IOC table.
SHA2566634339b813e6105b5138de6ab67b016b8dfbf49233c29de9bab3207e8b50d24Generation 2 loader that decrypts and reflectively loads config.bin.
SHA2566932a20ac61fd3f93d7cfee414f6f46834068ac7c9ca011b054a6a10dc56b3d1Additional campaign artifact explicitly listed in the host-based IOC table.
SHA2567462ce2595119c928cf516ec33148dc2a39dd9f71636a5c849c7ed93b7c5ca06update.zip archive containing the generation 2 FDMTP loader, payload, and sideloading executable.
SHA256795594ad5e6f2868cc4d8ed12dabf4f3999a1477c6b250527c5ede9a98528fb9Generation 2 loader that decrypts and reflectively loads update.bin.
SHA256a53d756f28457b1c4a239c91cdec8ed7b7da67a93e332e6df9621cbef8417474config.bin FDMTP payload artifact.
SHA256d9db5cbc193ddaf4c0a265804fdef70c32451daaf2974fa9adf52ce1defac5f7update.zip archive containing the generation 1 FDMTP loader and sideloading executable.
SHA256dc666e9c148bbca5e21d8c9a97143575c075f53360f135e0191aed9e8278d396Encrypted update.bin payload loaded by the generation 2 FDMTP loader.
URLhxxp[:]//cdns3[.]51quickfox[.]cn/2025090411/update[.]zipLoader download URL for the archive containing the FDMTP deployment components.

MITRE ATT&CK

T1010 · Application Window DiscoveryThe implant collects the window title of the topmost active program.T1016 · System Network Configuration DiscoveryFDMTP collects the endpoint IP address, gateway IP address, and MAC address.T1027 · Obfuscated Files or InformationThe initial JavaScript uses layered encoding and control-flow obfuscation; the second-generation .NET loader uses JieJie .NET Protector.T1033 · System Owner/User DiscoveryThe implant reports the current username to its C2 server.T1036.005 · Match Legitimate Resource Name or LocationInitial delivery infrastructure resembles legitimate QuickFox infrastructure, and the malicious JavaScript masquerades as Firebase SDK code.T1057 · Process DiscoveryThe loader checks tasklist output, and FDMTP retrieves process names and PIDs through EnumProcessByJson.T1059.003 · Windows Command ShellThe JavaScript loader invokes tasklist through cmd.exe child processes to inspect running applications.T1059.007 · JavaScriptJavaScript executed within QuickFox performs endpoint checks and downloads and launches subsequent infection components.T1071.001 · Web ProtocolsInitial downloads and implant registration use web requests to malicious delivery and staging domains.T1082 · System Information DiscoveryFDMTP collects Windows OS details, installation time, and the .NET Framework runtime version during registration.T1104 · Multi-Stage ChannelsWeb-based registration returns cluster addresses for subsequent socket-based FDMTP communications.T1105 · Ingress Tool TransferThe loader downloads update.zip, while server-delivered plugins can retrieve additional executable components.T1112 · Modify RegistryFDMTP stores compressed plugin executables under HKCU\SOFTWARE\Microsoft\IME\{Common.HostInfo.HWID} for later retrieval and execution.T1140 · Deobfuscate/Decode Files or InformationThe second-generation loader decrypts the FDMTP payload with AES-128-ECB, and implant modules and plugins are decompressed before loading.T1195.002 · Compromise Software Supply ChainThe QuickFox installer was compromised by adding downloader JavaScript to its embedded Electron renderer HTML.T1480 · Execution GuardrailsThe loader requires Windows, rejects endpoints running steam.exe, and proceeds only if a selected application process is present.T1518.001 · Security Software DiscoveryThe implant includes installed antivirus software in the host information sent to C2.T1574.001 · DLLThe article maps csmonitor.exe loading the malicious Microsoft.ServiceHosting.Tools.dll to this ID.T1620 · Reflective Code LoadingThe generation 2 loader reflectively loads the decrypted FDMTP payload, and the implant loads decompressed plugin assemblies.

People

Threat Actors

Malware

Vendors

Products

.NET FrameworkThis method is called when the .NET Framework can’t find a module that the client module is trying to load (i.e., when an ‘Assembly Resolve’ event is triggered).ElectronThe attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader.FortiClientFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiEDRFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiGateFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.FortiMailFortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service.Microsoft Azure SDK‘Microsoft.ServiceHosting.Tools.dll’, a trojanized version of Microsoft Azure SDK that contains an FDMTP payload embedded within the file itself.Microsoft WindowsAffected Platforms: Windows EndpointsQuickFoxImpact Parties: QuickFox UsersSogou Pinyin IMEcampaign, the adversary leveraged the legitimate ‘biz_render.exe’ binary, a legitimate component of Sogou Pinyin IME, as the sideloading target, with their loader replacing ‘browser_host.dll’, whereas in our case, theSteamThe script will stop and exit if a process named ‘steam.exe’ is in the tasklist output.Windows Azure Compute and Storage Emulatorfile that contains two components:‘csmonitor.exe’, a legitimate Microsoft binary ‘Windows Azure Compute and Storage Emulator’ used to sideload ‘Microsoft.ServiceHosting.Tools.dll’

Tools

Countries

Related Articles