{"id":26144,"date":"2026-09-21T13:06:13","date_gmt":"2026-09-21T21:06:13","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant-3\/"},"modified":"2026-09-21T13:06:13","modified_gmt":"2026-09-21T21:06:13","slug":"quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant-3","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant-3\/","title":{"rendered":"QuickFox Supply Chain Attack Used to Deploy FDMTP Implant"},"content":{"rendered":"<div class=\"Table-Content aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"blog-toc\">\n<div class=\"b3-blog-list__row\">\n<div class=\"b3-blog-list__column-left table-content-wrapper automatic\">\n<ul class=\"table-of-content\">\n<li class=\"header\"><img decoding=\"async\" alt=\"\" class=\"toc-icon\" src=\"\/content\/dam\/fortinet\/images\/toc-icon.jpg\"\/>Article Contents<\/li>\n<\/ul>\n<\/div>\n<div class=\"aem-GridColumn aem-GridColumn--default--8 b3-blog-list__column-right scrolling-content automatic\">\n<div class=\"b15-blog-meta__container text-container\">\n<span>By <\/span><br \/>\n<span class=\"b15-blog-meta__author\"><br \/>\n<a href=\"\/blog\/search?author=The+FortiGuard+Incident+Response+Team\">The FortiGuard Incident Response Team<\/a><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__\"><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__date\"> | August 04, 2026<\/span>\n<\/div>\n<div class=\"C875-Disclaimer\">\n<\/div>\n<div class=\"raw-import\">\n<div class=\"text-container\"><\/div>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p style=\"\tmargin-left: 80.0px;\n\"><b>Affected Platforms: <\/b>Windows Endpoints<br \/>\n<b>Impact Parties: <\/b>QuickFox Users<br \/>\n<b>Impact: <\/b>Supply chain attack resulting in the installation of an implant for persistent access.<br \/>\n<b>Severity Level: <\/b>Medium<\/p>\n<p>FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience.<\/p>\n<p>Active since at least August 2025, the supply chain attack involves a trojanized version of the QuickFox application. The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader. Upon execution, the JavaScript loader fingerprints the victim endpoint to determine if it\u2019s a valid target before downloading and installing an FDMTP implant. Analysis of infrastructure related to this campaign indicates active development, and infrastructure continues to be active at the time of publishing.<\/p>\n<p>Fortinet has contacted QuickFox as part of our responsible disclosure process. QuickFox has removed the described malicious components from their Windows installer from v3.59.6, and the malicious components that were later transferred to MacOS components do not result in the progression of the infection.<\/p>\n<h2>Infection Process<\/h2>\n<p>The infection chain associated with this supply chain attack is outlined in Figure 1 below. Note that two different \u2018generations\u2019 of the .NET loader employed at different stages of the intrusion were observed, with the deviations of each noted in Figure 1.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<div class=\"image-enlarge\">\n<a class=\"cmp-image--link\" data-title=\"Figure 1: The infection process associated with the observed QuickFox supply chain attack resulting in the deployment of the FDMTP implant.\" href=\"\/blog\/threat-research\/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant\/_jcr_content\/root\/responsivegrid\/table_content\/par\/image.img.jpeg\/1786047392387\/quickfox-diagram.jpeg\"><\/p>\n<p><\/a>\n<\/div>\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"true\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 1: The infection process associated with the observed QuickFox supply chain attack resulting in the deployment of the FDMTP implant.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Infection Chain Technical Analysis<\/h2>\n<p>The installer executable was trojanized by adding two lines of JavaScript to a single HTML file. This HTML file is executed by the Electron renderer, which is part of the main QuickFox application during initialization. The modified HTML file can be found nested within the archive embedded within the executable file at path \u2018<i>&lt;executable path&gt;\\&lt;version&gt;.7z\\resources\\app.asar\\candy\\core\\service\\index.html<\/i>\u2019. The two lines of JavaScript added to the file are shown in the screenshot in Figure 3, below, and a comparison of the original and the modified version is shown in Figure 2.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 2: Code comparison between legitimate \u2018index.html\u2019 HTML file within the installer (right image) and trojanized version (left image).<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p class=\"cq-text-placeholder-ipe\" data-emptytext=\"Text\">\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 3: Modified version of the index.html file within the QuickFox Electron application.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>These two added lines of JavaScript download and execute two JavaScript files from two URLs referencing the \u2018<i>cdns3[.]51quickfox[.]cn<\/i>\u2019 domain. Analysis of the domain identifies it was registered on 09 Jun 2025 by \u2018\u6797\u5929\u4fca (Lin Tianjun)\u2019. The domain appears to be an implementation of typosquatting that swaps the \u2018<i>.com<\/i>\u2019 TLD in the legitimate \u2018<i>cdns3[.]51quickfox[.]com<\/i>\u2019 with the \u2018<i>.cn<\/i>\u2019 TLD. To confirm, the \u2018<i>51quickfox[.]cn<\/i>\u2019 domain is not an official QuickFox domain. A comparison of the details related to the masquerading domain and the legitimate QuickFox domain is shown in Table 1.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-gray\">\n<th width=\"20%\">Attribute<\/th>\n<th width=\"40%\">Legitimate QuickFox Domain<\/th>\n<th width=\"40%\">Malicious Fake Domain<\/th>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">Domain<\/td>\n<td>51quickfox[.]com<\/td>\n<td>cdns3[.]51quickfox[.]cn<\/td>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">Registered Date<\/td>\n<td>2021-06-24<\/td>\n<td>2025-06-09<\/td>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">Registrant<\/td>\n<td>Xiamen Kezhengsai Technology<\/td>\n<td>\u6797\u5929\u4fca (Lin Tianjun)<\/td>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">Registrar<\/td>\n<td>GoDaddy (US)<\/td>\n<td>Web Commerce Communications Ltd (Malaysia)<\/td>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">DNS<\/td>\n<td>Alibaba Cloud DNS<\/td>\n<td>Cloudflare<\/td>\n<\/tr>\n<tr>\n<td class=\"bg-gray\">Certificates<\/td>\n<td>Standard DV<\/td>\n<td>Google Trust Services (issued same day as domain registration)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"\ttext-align: center;\n\tfont-size: 13.0px;\n\">Table 1: Comparison of domain details for the legitimate QuickFox infrastructure and the malicious masquerading domain.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Analysis of previous versions of the QuickFox installer indicates the trojanized components were introduced sometime between 2025-07-25 and 2025-08-13. The earliest affected version that FortiGuard Labs obtained was v3.0.51.0 for the Windows application. Analysis of available QuickFox application versions for Mac identified that the supply chain attack had resulted in the modified \u2018index.html\u2019 file being included in some builds. However, execution guardrails in the initial downloaded JavaScript restricted execution to Windows endpoints. Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users. Details of the compromised status of available versions are outlined in Table 2.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-gray\">\n<th width=\"25%\">Version (Windows)<\/th>\n<th width=\"50%\">Trojanized<\/th>\n<th width=\"25%\">First Observed<\/th>\n<\/tr>\n<tr>\n<td>3.0.29<\/td>\n<td>False<\/td>\n<td>2025-04-14<\/td>\n<\/tr>\n<tr>\n<td>3.0.30<\/td>\n<td>False<\/td>\n<td>2025-05-23<\/td>\n<\/tr>\n<tr>\n<td>3.0.35<\/td>\n<td>False<\/td>\n<td>2025-07-25<\/td>\n<\/tr>\n<tr>\n<td>3.51.0<\/td>\n<td>True<\/td>\n<td>2025-08-13<\/td>\n<\/tr>\n<tr>\n<td>3.52.0<\/td>\n<td>True<\/td>\n<td>2025-08-18<\/td>\n<\/tr>\n<tr>\n<td>3.55.0<\/td>\n<td>True<\/td>\n<td>2025-09-21<\/td>\n<\/tr>\n<tr>\n<td>3.55.5<\/td>\n<td>True<\/td>\n<td>2025-11-19<\/td>\n<\/tr>\n<tr>\n<td>3.59.0<\/td>\n<td>True<\/td>\n<td>2026-03-24<\/td>\n<\/tr>\n<tr>\n<td>3.59.3<\/td>\n<td>True<\/td>\n<td>2026-05-08<\/td>\n<\/tr>\n<tr>\n<td>3.59.5<\/td>\n<td>True<\/td>\n<td>2026-06-22<\/td>\n<\/tr>\n<tr>\n<td>3.59.6<\/td>\n<td>False \u2013 Removed following Fortinet notification<\/td>\n<td>2026-06-29<br \/>\n(Current version at time of writing)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"\ttext-align: center;\n\tfont-size: 13.0px;\n\">Table 2: Details of the affected version of the QuickFox installer. Note. QuickFox does not maintain a publicly accessible version release timeline or historic installers for their Windows applications, so these represent the versions publicly available at the time of this reporting and should not be considered an exhaustive list.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Analysis of the files served by the two URLs identified that \u2018<i>firebase-analytics-compat.js<\/i>\u2019 contains legitimate Google Firebase code. The \u2018<i>firebase-app-compat.js<\/i>\u2019 file is a heavily obfuscated JavaScript file masquerading as the legitimate Firebase SDK code. Obfuscation of JavaScript and HTML components within an Electron application like QuickFox is not anomalous, so the presence of obfuscated JavaScript is not itself anomalous. However, in this case, the downloaded JavaScript leverages a custom algorithm outlined below:<\/p>\n<ol>\n<li>Wrapper function \u2018<i>r1muVuL<\/i>\u2019 designed to bypass static analysis<\/li>\n<li>Ten parallel layers of base91 decryption with a distinct 91 char alphabet<\/li>\n<li>Layers of encoded strings resolved through a cached string table<\/li>\n<li>Flow obfuscation with nested switch statements<\/li>\n<\/ol>\n<p>A screenshot of some of the obfuscation is shown below in Figure 4.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<div class=\"image-enlarge\">\n<a class=\"cmp-image--link\" data-title=\"Figure 4: Obfuscated JavaScript within the fake \u2018firebase-app-compat.js\u2019 file served by masquerading QuickFox URL.\" href=\"\/blog\/threat-research\/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant\/_jcr_content\/root\/responsivegrid\/table_content\/par\/image_copy_170990561_860408203.img.png\/1785453310997\/fg4.png\"><\/p>\n<p><\/a>\n<\/div>\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"true\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 4: Obfuscated JavaScript within the fake \u2018firebase-app-compat.js\u2019 file served by masquerading QuickFox URL.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Analysis of the deobfuscated script identifies several key functions; the first is a check to validate the affected endpoint is running Windows. The second is a check with C2 to ensure an endpoint is not re-infected. The third is to generate a list of processes using the tasklist command via a cmd.exe child process. This tasklist is then analyzed for specific process names. The script will stop and exit if a process named \u2018<i>steam.exe<\/i>\u2019 is in the tasklist output. Steam is a popular gaming platform, and FortiGuard Labs assesses that this guardrail is likely to restrict deployment of later-stage payloads to corporate computers. The next check is for 26 other process names related to a broad range of personal and business functions. A complete list of the process names, the assumed associated applications, and their function is shown below in Table 3.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<th width=\"20%\">Process Name (Tasklist String)<\/th>\n<th width=\"25%\">Potential Target Application<\/th>\n<th width=\"55%\">Application Function<\/th>\n<\/tr>\n<tr>\n<td>xshell<\/td>\n<td>Xshell<\/td>\n<td>SSH, Telnet, and terminal emulator for remote server administration.<\/td>\n<\/tr>\n<tr>\n<td>finalshell<\/td>\n<td>FinalShell<\/td>\n<td>SSH client and server management tool with file transfer and monitoring features.<\/td>\n<\/tr>\n<tr>\n<td>MobaXterm<\/td>\n<td>MobaXterm<\/td>\n<td>Enhanced terminal for Windows with SSH, SFTP, X11 forwarding, and remote access tools.<\/td>\n<\/tr>\n<tr>\n<td>Tabby<\/td>\n<td>Tabby Terminal (formerly Terminus)<\/td>\n<td>Open-source terminal emulator supporting SSH and multiple shells.<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" width=\"138\">\n<p>navicat<\/p>\n<\/td>\n<td>Navicat<\/td>\n<td>Database administration and development tool for MySQL, PostgreSQL, SQL Server, Oracle, etc.<\/td>\n<\/tr>\n<tr>\n<td>dbeaver<\/td>\n<td>DBeaver<\/td>\n<td>Universal database client and SQL development tool.<\/td>\n<\/tr>\n<tr>\n<td>git.exe<\/td>\n<td>Git<\/td>\n<td>Version control system used for source code management.<\/td>\n<\/tr>\n<tr>\n<td>idea64.exe<\/td>\n<td>IntelliJ IDEA<\/td>\n<td>Java and multi-language integrated development environment (IDE).<\/td>\n<\/tr>\n<tr>\n<td>sublime_text<\/td>\n<td>Sublime Text<\/td>\n<td>Lightweight text and code editor.<\/td>\n<\/tr>\n<tr>\n<td>notepad++.exe<\/td>\n<td>Notepad++<\/td>\n<td>Text editor and source code editor for Windows.<\/td>\n<\/tr>\n<tr>\n<td>Code.exe<\/td>\n<td>Visual Studio Code<\/td>\n<td>Source code editor with debugging and extension support.<\/td>\n<\/tr>\n<tr>\n<td>Exodus.exe<\/td>\n<td>Exodus Wallet<\/td>\n<td>Cryptocurrency wallet for managing digital assets.<\/td>\n<\/tr>\n<tr>\n<td>Binance.exe<\/td>\n<td>Binance Desktop<\/td>\n<td>Cryptocurrency exchange client for trading and managing crypto assets.<\/td>\n<\/tr>\n<tr>\n<td>Ledger<\/td>\n<td>Ledger Live<\/td>\n<td>Application for managing Ledger hardware cryptocurrency wallets.<\/td>\n<\/tr>\n<tr>\n<td>Trezor<\/td>\n<td>Trezor Suite<\/td>\n<td>Application for managing Trezor hardware cryptocurrency wallets.<\/td>\n<\/tr>\n<tr>\n<td>telegram.exe<\/td>\n<td>Telegram Desktop<\/td>\n<td>Messaging and communication platform.<\/td>\n<\/tr>\n<tr>\n<td>SafeW.exe<\/td>\n<td>SafeW<\/td>\n<td>Secure messaging application, often positioned as a privacy-focused communication tool.<\/td>\n<\/tr>\n<tr>\n<td>\u7231\u7ffb\u8bd1<\/td>\n<td>Ai Fanyi (&#8220;Love Translate&#8221;)<\/td>\n<td>Chinese translation software; likely used for machine translation and localization tasks.<\/td>\n<\/tr>\n<tr>\n<td>HelloWorld<\/td>\n<td>Unknown \/ Potentially HelloWorldApi<\/td>\n<td>Potentially HelloWorld API tool used for language translation.<\/td>\n<\/tr>\n<tr>\n<td>Hello-GPT.exe<\/td>\n<td>Hello-GPT<\/td>\n<td>Chinese translation assistant software.<\/td>\n<\/tr>\n<tr>\n<td>\u6d77\u738b\u51fa\u6d77<\/td>\n<td>Haiwang Chuhai<\/td>\n<td>Chinese cross-border e-commerce or overseas marketing tool; exact product identification may vary.<\/td>\n<\/tr>\n<tr>\n<td>\u6613\u7ffb\u8bd1<\/td>\n<td>Yi Fanyi<\/td>\n<td>Chinese translation software used for multilingual content translation.<\/td>\n<\/tr>\n<tr>\n<td>CC\u7ffb\u8bd1<\/td>\n<td>CC Translation<\/td>\n<td>Chinese translation\/localization utility. Exact vendor uncertain.<\/td>\n<\/tr>\n<tr>\n<td>\u5feb\u7ffb\u8bd1<\/td>\n<td>Kuai Fanyi (&#8220;Quick Translate&#8221;)<\/td>\n<td>Chinese translation software for rapid text translation.<\/td>\n<\/tr>\n<tr>\n<td>posend<\/td>\n<td>Posend<\/td>\n<td>Chinese customer service chat assistant software<\/td>\n<\/tr>\n<tr>\n<td>\u6d77\u8bd1\u901a.exe<\/td>\n<td>HaiYiTong<\/td>\n<td>Chinese translation\/localization software often used for cross-border e-commerce operations.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"\ttext-align: center;\n\tfont-size: 13.0px;\n\">Table 3: Process names and likely associated application and application function.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Once the script has confirmed that Steam is not running and that at least one of the applications in the above list are running the script will then download the next stage payload. Pseudocode for this section of the deobfuscated JavaScript is shown below in Figure 5.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 5: Pseudocode outlining deobfuscated JavaScript used to implement process related guardrails and download of next stage.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Note that, because QuickFox is an Electron application, JavaScript files are executed in the context of a dedicated child process spawned under the main QuickFox application process. This alters the process lineage for the infection process outlined above and should be considered when assessing protections from EDR and other technologies. The process tree associated with guardrail validation is very noisy, with a significant number of cmd.exe processes spawning from the child QuickFox process. A screenshot of the infection process lineage is shown in Figure 6 along with annotations for key infection stages.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 6: Process tree associated with the execution of the trojanized QuickFox installer. Note that the large number of QuickFox.exe child processes spawned is a result of Electron app design and is not inherently malicious.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The next stage of the JavaScript involves downloading the zip file \u2018<i>update.zip<\/i>\u2019 from the previous C2 via a web request to \u2018<i>hxxp:\/\/cdns3[.]51quickfox[.]cn\/2025090411\/update.zip<\/i>\u2019 and saving it to \u2018<i>%TEMP%\\quickfox\\update.zip\u2019<\/i>. FortiGuard Labs has identified at least two generations of the next stage of the intrusion, both of which execute an FDMTP payload:<\/p>\n<ol>\n<li>Generation 1 \u2013 Available from at least September 2025 \u2013 involves an \u2018update.zip\u2019 file that contains two components:\n<ul>\n<li><i>\u2018csmonitor.exe<\/i>\u2019, a legitimate Microsoft binary \u2018Windows Azure Compute and Storage Emulator\u2019 used to sideload \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019<\/li>\n<li>\u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019, a trojanized version of Microsoft Azure SDK that contains an FDMTP payload embedded within the file itself.<\/li>\n<\/ul>\n<\/li>\n<li>Generation 2 \u2013 Available from May 2026 \u2013 involves an \u2018<i>update.zip<\/i>\u2019 file that contains three components:\n<ul>\n<li>\u2018<i>csmonitor.exe<\/i>\u2019, a legitimate Microsoft binary \u2018Windows Azure Compute and Storage Emulator\u2019 used to sideload \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019<\/li>\n<li>\u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019, a custom loader that decrypts and executes the FDMTP payload contained within \u2018<i>update.bin<\/i>\u2019<\/li>\n<li>\u2018<i>update.bin<\/i>\u2019, an AES128-ECB encrypted payload file containing the FDMTP payload.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>In both generations, the prior JavaScript extracts the contents of the downloaded \u2018<i>update.zip<\/i>\u2019 to the \u2018<i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>\u2019 directory. Following extraction, the script creates a 1-byte file \u2018<i>data.dat<\/i>\u2019 in the updated directory. This file serves as a file-based mutex, and the script will exit if the file already exists to prevent re-infection. The script then executes \u2018<i>csmonitor.exe\u2019,<\/i> which sideloads the malicious \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019 DLL.<\/p>\n<h2>Unpacking the FDMTP Implant<\/h2>\n<h3>Initial loader execution<\/h3>\n<p>The behavior of this \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019 loader changes between generations, indicating ongoing development to improve the campaign\u2019s survivability.<\/p>\n<p>Analysis of the generation 1 version of the \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019 file (SHA256:2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C) identifies it as a .NET loader containing an embedded .NET module payload \u2018<i>Client.dll<\/i>\u2019 stored as a byte array. When executed through the csmonitor.exe application, the .NET loader instantiates an instance of the \u2018<i>DevStore<\/i>\u2019 class, which loads and executes the embedded \u2018<i>Client.dll<\/i>\u2019 as a new thread within the context of the csmonitor.exe process. A code snippet of key components of the <i>DevStore<\/i> class from the \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019 file is shown below, in Figure 7.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 7: Details of the \u2018Microsoft.ServiceHosting.Tools.dll\u2019 DLL. Note the \u2018DevStore\u2019 class and the embedded bytes that represent the \u2018Client.dll\u2019 .NET payload.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The generation 2 sample of \u2018<i>Microsoft.ServiceHosting.Tools.dll<\/i>\u2019 (SHA256:795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9) functions differently from the generation 1 sample. The generation 2 sample is obfuscated using the JieJie .NET Protector tool<sup>1<\/sup>\u00a0and functions as a loader to decrypt and load the contents of \u2018<i>update.bin<\/i>\u2019. The \u2018<i>update.bin<\/i>\u2019 file is encrypted using AES-128-ECB encryption with a common, hardcoded key \u2018<i>POt_L[Bsh0=+@0a.<\/i>\u2019 Note that this is the same decryption key observed in the previous FDMTP campaign reported by Darktrace. The decrypted contents of this file are a copy of the final FDMTP payload \u2018<i>Client.dll<\/i>\u2019 and functionally match those loaded in generation 1.<\/p>\n<h3>Operation of the FDMTP implant<\/h3>\n<p>The <i>Client.dll<\/i> payload contains 15 compressed modules within its resources section, as shown in Figure 8 below.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 8: Code snippet showing compressed modules within the \u2018Client.dll\u2019 resources section and the ResolveAssembly method. Note that this Client.dll assembly was loaded via the generation 1 loader, so it includes references to \u2018costura\u2019. This was not present in generation 2, but the FDMTP implants are functionally the same.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>On execution, it registers a \u2018<i>ResolveEventHandler<\/i>\u2019 object that points to the \u2018<i>Costura.AssemblyLoader.ResolveAssembly()\u2019<\/i> method as shown above in Figure 8. This method is called when the .NET Framework can\u2019t find a module that the client module is trying to load (i.e., when an \u2018Assembly Resolve\u2019 event is triggered). When called, this method decompresses and loads the corresponding module from the module resource section. This functionality obfuscates code within the compressed modules, reducing the effectiveness of static analysis methods.<\/p>\n<p>Each of these 15 modules contains specific functionality used during the operation of the FDMTP payload, but the main module that orchestrates the payload execution is \u2018<i>Client.FDMTPFrame.dll<\/i>\u2019.<\/p>\n<h3>FDMTP implant operation<\/h3>\n<p>Following the registration of this handler, the FDMTP implant attempts to obtain a C2 connection via the \u2018Client.Program.InitConnect() method, as shown in Figure 9 below.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 9: The code snippet from the Client.Program.InitConnect() method used to establish the initial connection to the FDMTP infrastructure.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>This method defines two RPC servers (CommonService and PluginService) and three plugins (FileTransferPlugin, SystemEventsPlugin, and ActiveWindowPlugin) for retrieving information from a hardcoded staging C2 via an API request \u2018<i>GET \/GetCluster?protocol=DotNet-TcpFDMTP&amp;tag=&lt;campaign&gt;<\/i>\u2019 to a staging domain, which in the analyzed sample here was \u2018<i>www[.]icloud-cdn[.]net<\/i>\u2019. This request registers the affected endpoint with the C2 using a country code (&lt;campaign&gt;) and retrieves an array of nodes (IP addresses and ports) used for subsequent DTMP C2 communications.<\/p>\n<p>The staging domain used to provide the IP and ports of FDMTP clusters is hardcoded within each sample. The FortiGuard Labs team identified several domains being used as staging domains associated with the QuickFox supply chain compromise, with at least three still active when QuickFox was notified of the compromise. The infrastructure related to this campaign continues to evolve the contents of \u2018<i>update.zip\u2019,<\/i> changing along with subsequent malware file names. Internal names within tooling appear consistent. The API function names also appear to be changing over time, with \u2018<i>GetSlaver<\/i>\u2019, \u2018<i>GetGateways<\/i>\u2019, \u2018<i>GetEndpoints<\/i>\u2019 \u2018<i>GetServers<\/i>\u2019, \u2018<i>GetHosts<\/i>\u2019, and \u2018<i>GetNodes<\/i>\u2019 all observed performing similar functions. These C2 staging domains, along with some of their associated URLs, are shown in Table 4.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<th width=\"20%\">Domain<\/th>\n<th width=\"50%\">Associated URLs<\/th>\n<th width=\"15%\">First Observed<\/th>\n<th width=\"15%\">Last Observed<\/th>\n<\/tr>\n<tr>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/dfsvc.exe.config<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/dnscfg.dll<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/vshost.exe<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/GetCluster?protocol=Dotnet-TcpDmtp&amp;tag=&lt;campaign&gt;&amp;uid=&lt;victim&gt;<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/dfsvc.exe<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll<br \/>\nwww[.]yahoo-cdn[.]it[.]com\/config.etl<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>www[.]google-apis[.]net<\/td>\n<td>www[.]google-apis[.]net\/dfsvc.exe<br \/>\nwww[.]google-apis[.]net\/dfsvc.exe.config<br \/>\nwww[.]google-apis[.]net\/wangmeng.dll<\/td>\n<td>2026-01-18<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>www[.]icloud-cdn[.]net<\/td>\n<td>www[.]icloud-cdn[.]net\/GetSlaver<br \/>\nwww[.]icloud-cdn[.]net\/checksum.bin<\/td>\n<td>2025-11-17<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>www[.]wangmeng[.]xyz<\/td>\n<td>www[.]wangmeng[.]xyz\/GetGateways<br \/>\nwww[.]wangmeng[.]xyz\/GetVips<br \/>\nwww[.]wangmeng[.]xyz\/GetPeers<br \/>\nwww[.]wangmeng[.]xyz\/GetMembers<br \/>\nwww[.]wangmeng[.]xyz\/GetNodes<br \/>\nwww[.]wangmeng[.]xyz\/GetTargets<br \/>\nwww[.]wangmeng[.]xyz\/GetReplicas<br \/>\nwww[.]wangmeng[.]xyz\/GetServers<br \/>\nwww[.]wangmeng[.]xyz\/GetRoutes<br \/>\nwww[.]wangmeng[.]xyz\/GetAgents<br \/>\nwww[.]wangmeng[.]xyz\/GetMachines<br \/>\nwww[.]wangmeng[.]xyz\/GetEndpoints<br \/>\nwww[.]wangmeng[.]xyz\/GetWorkers<br \/>\nwww[.]wangmeng[.]xyz\/GetInstances<\/td>\n<td>2025-11-19<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>www[.]wangmengsb[.]com<\/td>\n<td>www[.]wangmengsb[.]com\/GetEndpoints<br \/>\nwww[.]wangmengsb[.]com\/GetNodes<br \/>\nwww[.]wangmengsb[.]com\/GetBackends<br \/>\nwww[.]wangmengsb[.]com\/GetNodes<br \/>\nwww[.]wangmengsb[.]com\/GetIps<br \/>\nwww[.]wangmengsb[.]com\/GetAgents<br \/>\nwww[.]wangmengsb[.]com\/GetHosts<br \/>\nwww[.]wangmengsb[.]com\/GetReplicas<br \/>\nwww[.]wangmengsb[.]com\/GetVips<br \/>\nwww[.]wangmengsb[.]com\/GetAddresses<br \/>\nwww[.]wangmengsb[.]com\/GetPeers<br \/>\nwww[.]wangmengsb[.]com\/GetWorkers<br \/>\nwww[.]wangmengsb[.]com\/GetRoutes<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-16<\/td>\n<\/tr>\n<tr>\n<td>www[.]wangmeng66[.]top<\/td>\n<td>www[.]wangmeng66[.]top\/GetWorkers<br \/>\nwww[.]wangmeng66[.]top\/GetRoutes<br \/>\nwww[.]wangmeng66[.]top\/GetAddresses<br \/>\nwww[.]wangmeng66[.]top\/GetEndpoints<br \/>\nwww[.]wangmeng66[.]top\/GetResources<br \/>\nwww[.]wangmeng66[.]top\/GetInstances<br \/>\nwww[.]wangmeng66[.]top\/GetProxies<br \/>\nwww[.]wangmeng66[.]top\/GetMachines<br \/>\nwww[.]wangmeng66[.]top\/GetServers<br \/>\nwww[.]wangmeng66[.]top\/GetTargets<br \/>\nwww[.]wangmeng66[.]top\/GetPeers<br \/>\nwww[.]wangmeng66[.]top\/GetHosts<br \/>\nwww[.]wangmeng66[.]top\/GetReplicas<\/td>\n<td>2026-06-20<\/td>\n<td>2026-06-26<\/td>\n<\/tr>\n<tr>\n<td>www[.]techcheck1[.]com<\/td>\n<td>www[.]techcheck1[.]com\/config.etl<br \/>\nwww[.]techcheck1[.]com\/wangmeng.dll<br \/>\nwww[.]techcheck1[.]com\/Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll<br \/>\nwww[.]techcheck1[.]com\/vshost.exe<br \/>\nwww[.]techcheck1[.]com\/GetPeers<br \/>\nwww[.]techcheck1[.]com\/GetClusterNodes<\/td>\n<td>2026-06-26<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"\ttext-align: center;\n\tfont-size: 13.0px;\n\">Table 4: Domains and associated URLs used as staging domains for the FDMTP implants associated with this QuickFox campaign infrastructure.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The FortiGuard Labs team observed that staging domains responded to this request with a base64-encoded and gzip-compressed list of two IP:Port entries per request, with port ranges observed between 20800 and 20816. An example of web traffic associated with this target registration is shown in Figure 10.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 10: Traffic example associated with an FDMTP implant requesting and retrieving C2 node data from the staging domain.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Once the implant has received the C2 connection information, it establishes a connection to the C2 clusters through a FDMTP socket, as shown in Figure 9 above. The FortiGuard Labs team identified the following clusters\/nodes (see Table 5) associated with some of the staging domains outlined in Table 4.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<th width=\"30%\">Cluster\/Node IP<\/th>\n<th width=\"40%\">Associated Staging Domain<\/th>\n<th width=\"15%\">First Observed<\/th>\n<th width=\"15%\">Last Observed<\/th>\n<\/tr>\n<tr>\n<td>47[.]238[.]64[.]56<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>2026-03-27<\/td>\n<td>2026-06-11<\/td>\n<\/tr>\n<tr>\n<td>47[.]239[.]93[.]49<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\n<\/td>\n<td>2026-01-21<\/td>\n<td>2026-01-21<\/td>\n<\/tr>\n<tr>\n<td>47[.]239[.]4[.]179<\/td>\n<td>www[.]wangmengsb[.]com<br \/>\nwww[.]techcheck1[.]com<br \/>\nwww[.]google-apis[.]net<\/td>\n<td>2026-06-08<br \/>\n2026-06-08<br \/>\n2026-05-21<\/td>\n<td>2026-06-08<br \/>\n2026-06-08<br \/>\n2026-05-22<\/td>\n<\/tr>\n<tr>\n<td>47[.]88[.]21[.]252<\/td>\n<td>www[.]google-apis[.]net<\/td>\n<td>2026-05-21<\/td>\n<td>2026-05-22<\/td>\n<\/tr>\n<tr>\n<td>47[.]238[.]240[.]219<\/td>\n<td>www[.]wangmengsb[.]com<br \/>\nwww[.]techcheck1[.]com<\/td>\n<td>2026-06-08<br \/>\n2026-06-08<\/td>\n<td>2026-06-08<br \/>\n2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>154[.]223[.]75[.]206<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>2025-01-21<\/td>\n<td>2025-01-21<\/td>\n<\/tr>\n<tr>\n<td>154[.]223[.]58[.]64<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>45[.]158[.]180[.]250<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>154[.]223[.]58[.]142<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>38[.]60[.]142[.]56<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<br \/>\nwww[.]icloud-cdn[.]net<\/td>\n<td>2026-02-13<br \/>\n2025-11-17<\/td>\n<td>2026-06-19<br \/>\n2026-06-30<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"\ttext-align: center;\n\tfont-size: 13.0px;\n\">Table 5: FDMTP cluster nodes associated with identified staging C2 domains.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Once the running implant is connected to the C2 cluster, it conducts an FDMTP handshake by sending \u2018<i>00 01<\/i>\u2019 and \u2018<i>00 04<\/i>\u2019 flag packets with negotiation types, IDs, and status. Afterward, the C2 server sends a \u2018<i>GetInfo<\/i>\u2019 RPC request within a \u2018<i>00 14<\/i>\u2019 flag packet to the implant to collect basic information from the victim\u2019s device. The malware serializes and compresses the basic information and sends it as a response in a \u2018<i>00 15<\/i>\u2019 packet. An example of the two packets collected during analysis is shown in Figure 11.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 11: Calling the GetInfo() RPC.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>When the implant receives this \u2018<i>GetInfo<\/i>\u2019 RPC request, the <i>Client.CommonService.GetInfo()<\/i> method is called based on the RPC server\u2019s registry information. It sends the basic information stored in the <i>Common.HostInfo<\/i> variable, which contains the data as shown in Figure 12 below.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 12: Example of basic information obtained from a compromised device and sent to C2 server as part of the \u2018GetInfo\u2019 method called during installation.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>It contains:<\/p>\n<ul>\n<li>The window title of the topmost active program<\/li>\n<li>Installed AV software<\/li>\n<li>Client Type<\/li>\n<li>.NET Framework runtime version<\/li>\n<li>Network information, including the IP address, gateway IP address, and MAC address<\/li>\n<li>Windows OS information and the installation date and time for the current endpoint<\/li>\n<li>Current username.<\/li>\n<li>Implant information including file full path, version, process ID, and hosting process name<\/li>\n<\/ul>\n<p>The malware compresses the data list above and sends it to the C2 server over a \u2018<i>00 15<\/i>\u2019 flag packet, as illustrated at the bottom of Figure 11. The C2 server then sends an \u2018<i>EnumProcessByJson<\/i>\u2019 RPC request to collect all running process information from the compromised endpoint, including the PIDs and process names. This is likely to perform additional server-side filtering of compromised endpoints and to support adversary targeting.<\/p>\n<p>The implant continued to periodically connect to FDMTP infrastructure. The implant appears to operate largely through plugins (DLLs) that are pushed from the FDMTP server to the implant during check-ins. When the adversary needs to execute a remote plugin on the compromised device, the C2 server sends \u2018<i>IsRegistryPlugin<\/i>\u2019, \u2018<i>RegistryPlugin\u2019<\/i> and \u2018<i>RunPlugin\u2019<\/i> RCP requests within packets marked with the \u2018<i>00 14<\/i>\u2019 flag.<\/p>\n<h4>IsRegistryPlugin<\/h4>\n<p>The C2 server sends a plugin\u2019s hash code to the operating implant as the parameter to the <i>IsRegistryPlugin()<\/i> method, which invokes the corresponding \u2018<i>Client.FDMTPFrame.Connection.PluginService.IsRegistryPlugin()<\/i>\u2019 with the DLL file hash code as its parameter. The operating implant then checks whether the corresponding plugin has already been stored in the compromised device\u2019s registry.<\/p>\n<p>It then reports the result (\u2018<i>00<\/i>\u2019 indicates not found; \u2018<i>01<\/i>\u2019 indicates found) back to the C2 server within a \u2018<i>00 15<\/i>\u2019 flag packet, as shown in Figure 13.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 13: Packets associated with the \u2018IsRegistryPlugin\u2019 RPC request.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h4>RegistryPlugin<\/h4>\n<p>If the C2 server receives a \u2018<i>00<\/i>\u2019 response to the \u2018<i>IsRegistryPlugin\u2019<\/i> request, it sends a \u2018<i>RegistryPlugin<\/i><b>\u2019<\/b> RPC request to the FDMTP server. The corresponding RPC request response contains a compressed executable file embedded within the packet, as shown below in Figure 14.<\/p>\n<p>On receipt of this response, the \u2018<i>Client.FDMTPFrame.Connection.PluginService.RunPlugin()\u2019<\/i> method is invoked to save the compressed executable file into the system registry under the specific sub-key \u2018<i>HKCU\\SOFTWARE\\Microsoft\\IME\\{Common.HostInfo.HWID}<\/i>\u2019.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 14: Packets associated with the RegistryPlugin RPC request.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>If the server receives a \u2018<i>01<\/i>\u2019 in response to the \u2018<i>IsRegistryPlugin\u2019<\/i> request, or once the response to the \u2018<i>RegistryPlugin<\/i><b>\u2019<\/b> request has been saved to the registry, the C2 server proceeds directly with a <b>\u2018<i>RunPlugin\u2019<\/i><\/b> RPC request.<\/p>\n<h4>RunPlugin<\/h4>\n<p>When the implant receives a \u2018<i>RunPlugin\u2019<\/i> RPC request, the \u2018<i>Client.FDMTPFrame.Connection.PluginService.RunPlugin()<\/i>\u2019 method is invoked. The corresponding packet contains a hash of the target plugin\u2019s compressed file code corresponding to the target plugin that is passed to the \u2018<i>Client.FDMTPFrame.Connection.PluginService.RunPlugin()<\/i>\u2019 method. Within the method, the implant first retrieves the plugin file from the system registry using its hash, then decompresses and loads it. Finally, the plugin\u2019s \u2018<i>Plugin.Room.run()<\/i>\u2019 method is invoked. In the sample analyzed during testing, the loaded plugin file is named \u2018<i>Assist.dll<\/i>\u2019. When its \u2018<i>Plugin.Room.run()<\/i>\u2019 method is invoked, it calls the \u2018<i>Handle()<\/i>\u2019 method to process the decompressed parameter stored in the \u2018<i>pluginMethod\u2019<\/i> variable, as shown in Figure 15.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 15: Processing the decompressed parameter originally contained in the \u2018RunPlugin\u2019 RPC request packet.<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>In the case of the plugin sample analyzed during our investigation, the \u2018<i>Assist.dll<\/i>\u2019 plugin downloads two files and saves them to the \u2018<i>%LocalAppData%\\Microsoft\\WindowsApps<\/i>\u2019 folder. Once downloaded, the C2 server can issue a \u2018<i>StartProcess<\/i>\u2019 RPC request to execute the downloaded files. It should be noted that these URLs used to retrieve subsequent executable components are embedded within the server-provided plugin and are configurable between campaigns, allowing some additional survivability for running implants.<\/p>\n<p>FortiGuard Labs did not observe significant post-exploitation behavior from the FDMTP implant on affected victims following initial installation beyond basic enumeration performed through the previously described plugin functionality. The FortiGuard Labs team did not observe any additional plugins beyond those reported by Darktrace in previous FDMTP reporting.<\/p>\n<h2>Vendor Engagement and Response<\/h2>\n<p>FortiGuard Incident Response has engaged with the affected vendor, per our responsible disclosure program. QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack. Currently identified affected versions apply to the Windows applications only at this stage, and versions &gt;v3.0.35 (the earliest known non-compromised version) and &lt;v3.55.6, the most recent version in which QuickFox has removed malicious components.<\/p>\n<h2>Attribution<\/h2>\n<p>FortiGuard Labs does not confidently attribute this campaign to a particular actor. However, there is significant technical crossover with open-source reporting that is externally attributed to Twill Typhoon. Details of this technical crossover are outlined below.<\/p>\n<h3>Twill Typhoon<\/h3>\n<p>Reporting by Darktrace highlights the recent use of an FDMTP implant matching the final payload deployed in the campaign related to the QuickFox supply chain compromise. Matches were based on side-loading techniques (<a aria-label=\"T1574.001 \u2013 Hijack Execution Flow: DLL\" href=\"https:\/\/attack.mitre.org\/techniques\/T1574\/001\/\" rel=\"noopener noreferrer\" target=\"_blank\">T1574.001 \u2013 Hijack Execution Flow: DLL<\/a>), code structure, and key loader components. In this previously reported campaign, the adversary leveraged the legitimate \u2018biz_render.exe\u2019 binary, a legitimate component of Sogou Pinyin IME, as the sideloading target, with their loader replacing \u2018browser_host.dll\u2019, whereas in our case, the adversary leveraged the \u2018csmonitor.exe\u2019 application as a target for sideloading.<\/p>\n<p>In addition to this technique implementation crossover, there is shared infrastructure between the two campaigns, as C2 \u2018cluster\u2019 IPs provided by staging domains observed in this previously reported campaign were also registered as C2 \u2018cluster\u2019 IPs linked to staging domains observed in the campaign we highlighted above. Linkages here are entirely related to technical factors, indicating with high confidence that the same infrastructure and tooling were employed across the two reported campaigns.<\/p>\n<p>An additional consideration regarding attribution is the inclusion of partial victim filtering at the client level. The JavaScript executed through the trojanized HTML code responsible for the initial C2 connection includes execution guardrails that kill the infection if an executable named \u2018<i>steam.exe<\/i>\u2019 is running. FortiGuard Labs assesses that this is likely intended to avoid deployment on endpoints used for personal use, increasing the likelihood of the second-stage payload only being deployed in corporate environments. Additionally, the initial JavaScript installs the payload only if one of a list of processes (see Table 3) is present. The list includes several processes associated with administrator tooling, translator applications focused on Chinese-native translators, developer tools, and crypto-related applications. This collection of applications does not provide definitive validation of targeting, as a broad range of motivations can be supported by targeting the processes in the targeted list. However, the list does contain a large percentage of Chinese translation applications<\/p>\n<p>QuickFox\u2019s user base is primarily Chinese international students and expats who use the application to more efficiently interact with Chinese-based services. Given this user base, a hypothesis around targeting is that primary targeting was generically for Chinese citizens operating outside China. A competing hypothesis is that this campaign aimed to target professionals required to interact with Chinese native speakers, potentially for trade or diplomatic engagement purposes. Neither hypothesis can be confirmed without understanding the victim context for second-stage intrusions, which would identify true targets of the campaign.<\/p>\n<h2>Conclusion<\/h2>\n<p>This campaign highlights the need for organizations to adequately prepare against supply chain attacks, especially those targeting specific user bases that may not sit within an organization\u2019s typical threat profile. Additionally, the TTP and indicator crossover related to this campaign and the campaign reported by Darktrace earlier in 2026 highlight how the application of timely, high-confidence open-source threat intelligence can, in some cases, provide detection opportunities across adversary campaigns.<\/p>\n<p>The lack of confidence in attribution beyond technical clustering is largely due to limited visibility into second-stage post-exploitation activity. Despite identifying several victims of this initial infection, this initial part of the campaign (up to and including FDMTP implant installation) appears opportunistic, with the information gathered centralized, likely for second-stage target validation.<\/p>\n<p>FortiGuard Labs is continuing to investigate infrastructure associated with this larger campaign to fill some of these intelligence gaps and identify other potentially related supply chain attacks. If you believe this or any other cybersecurity threat has impacted your organization, please contact our <a href=\"https:\/\/www.fortinet.com\/corporate\/about-us\/contact-us\/experienced-a-breach\">Global FortiGuard Incident Response Team<sup>2<\/sup><\/a><\/p>\n<h2>Fortinet Protections<a aria-label=\"Global FortiGuard Incident Response Team\" href=\"\/corporate\/about-us\/contact-us\/experienced-a-breach\" title=\"Global FortiGuard Incident Response Team\"><\/a><\/h2>\n<p>FortiGuard Antivirus signatures associated with indicators related to this investigation are provided in the IOC section below. FortiGate, FortiMail, FortiClient, and FortiEDR support ingestion of signatures from the FortiGuard AntiVirus service. As a result, customers who have these products with up-to-date protections are protected.<\/p>\n<p>The URLs are rated as \u201cMalicious Websites\u201d and \u201cMalicious Activities Found\u201d by the FortiGuard Web Filtering service.<\/p>\n<p>FortiGuard IP Reputation and Anti-Botnet Security Service proactively block these intrusions by aggregating malicious source IP data from the Fortinet distributed network of threat sensors, CERTs, MITRE, cooperative competitors, and other global sources that collaborate to provide up-to-date threat intelligence about hostile sources.<\/p>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>MITRE ATT&amp;CK Mapping<\/h2>\n<p><b>TA0001: Initial Access\u00a0<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1195.002<\/td>\n<td>Supply Chain Compromise: Compromise Software Supply Chain<\/td>\n<td>QuickFox application compromised through the introduction of malicious JavaScript within embedded Electron renderer HTML file bundled into legitimate QuickFox application. Affected versions &gt;3.0.35 and &lt;3.55.6.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>TA0002: Execution\u00a0<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique\u00a0\u00a0<\/td>\n<td width=\"30%\">Technique Description\u00a0<\/td>\n<td width=\"50%\">Observed Activity\u00a0\u00a0<\/td>\n<\/tr>\n<tr>\n<td>T1059.007\u00a0<\/td>\n<td>Command and Scripting Interpreter: JavaScript<\/td>\n<td>Obfuscated JavaScript running in the context of QuickFox Electron application used across multiple stages of infection. JavaScript is downloaded from staging C2 domain prior to execution.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>TA0003: Persistence\u00a0<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1112<\/td>\n<td>Modify Registry<\/td>\n<td>FDMTP implant can store encrypted assembly modules used for various command execution tasks within the registry under the \u2018<i>HKCU\\SOFTWARE\\Microsoft\\IME\\{Common.HostInfo.HWID}<\/i>\u2019 sub-key. Each sub-key value and data pair represents a different module that was executed through the implant. We did not identify any additional modules beyond previous Darktrace reporting.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>TA0005: Stealth<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1574.001<\/td>\n<td>Hijack Execution Flow: DLL<\/td>\n<td>The Windows Azure Simulation Monitor application, \u2018csmonitor.exe\u2019, is targeted for DLL sideloading a malicious file named \u2018Microsoft.ServiceHosting.Tools.dll\u2019 as part of this campaign. In this case the target executable and malicious payload were saved to the \u2018%APPDATA%\\Local\\Temp\\quickfox\\updated\\\u2019 directory<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1480<\/td>\n<td>Execution Guardrails<\/td>\n<td>JavaScript retrieves initial process listing using a tasklist child process to determine if Steam, \u2018steam.exe\u2019, is running and if at least one of the applications listed in Table 3 is running. If Steam is running or none of the listed applications are running, the infection process will end.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1036.005<\/td>\n<td>Masquerading: Match Legitimate Resource Name or Location<\/td>\n<td>Initial domains employed during initial loader components attempt to masquerade as legitimate QuickFox infrastructure. This is likely to avoid detection by QuickFox developers and users who may observe anomalous web traffic from the QuickFox application.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>TA0007: Discovery\u00a0<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1057<\/td>\n<td>Process Discovery\u00a0<\/td>\n<td>The initial JavaScript loader performs process discovery to enforce execution guardrails. Additionally, later stage FDMTP payload collects basic information on the infected endpoint for target registration with C2.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>TA0011: Command &amp; Control\u00a0\u00a0<\/b><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1071.001\u00a0<\/td>\n<td>Application Layer Protocol: Web Protocols\u00a0\u00a0<\/td>\n<td>C2 communications are initially through web requests to malicious domains.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"bg-red\">\n<td width=\"20%\">Technique<\/td>\n<td width=\"30%\">Technique Description<\/td>\n<td width=\"50%\">Observed Activity<\/td>\n<\/tr>\n<tr>\n<td>T1104\u00a0\u00a0<\/td>\n<td>Multi-Stage Channels<\/td>\n<td>Initial C2 used by loaders and to register targets with C2 is web protocol based, but FDMTP implant communicates via TouchSocket Duplex Message Transport Protocol (FDMTP) to \u2018cluster\u2019 IPs retrieved during registration. Communication to these clusters was observed on ports 20800-208016 for this campaign.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Indicators of Compromise<\/h2>\n<p>The following lists of indicators are associated with the campaign outline in this article.<\/p>\n<h3>Network Indicators<\/h3>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"indicators-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<th width=\"5%\">Indicator Type<\/th>\n<th width=\"25%\">Value<\/th>\n<th width=\"46%\">Description<\/th>\n<th width=\"12%\">First Observed<\/th>\n<th width=\"12%\">Last Observed<\/th>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>cdns3[.]51quickfox[.]cn<\/td>\n<td>Masquerading as a QuickFox domain but is malicious. Hosts initial components of infection started through supply chain compromise of QuickFox installer.<\/td>\n<td>2025-07-24<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>cdns3[.]51quickfox[.]cn\/2025090411\/update.zip<\/td>\n<td>URL for downloading zip file containing side loading target (<i>csmonitor.exe<\/i>), .NET loader (<i>Microsoft.ServiceHosting.Tools.dll<\/i>) and encrypted FDMTP payload (<i>update.bin<\/i>)[only present in gen 2].<\/td>\n<td>2025-07-24<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>cdns3[.]51quickfox[.]cn\/script\/firebase-app-compat.js<\/td>\n<td>URL for downloading the initial JavaScript loader. Embedded within index.html file modified as part of supply chain attack.<\/td>\n<td>2025-07-24<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>cdns3[.]51quickfox[.]cn\/script\/firebase-analytics-compat.js<\/td>\n<td>URL for downloading legitimate Google Firebase script. Embedded within index.html file modified as part of supply chain attack. Hosted file is not malicious but a decoy to attempt to hide supply chain attack.<\/td>\n<td>2025-07-24<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]icloud-cdn[.]net<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure. Previously reported by Darktrace.<\/td>\n<td>2025-09-18<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net:8080\/GetCluster<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2025-08-07<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net:8080\/GetSlaver<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2025-09-18<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net\/checksum.bin<\/td>\n<td>URL to retrieve FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2026-04-15<\/td>\n<td>2026-04-15<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net\/dnscfg.dll<\/td>\n<td>URL to retrieve FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2025-10-03<\/td>\n<td>2026-05-28<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net\/Client.dll<\/td>\n<td>URL to retrieve FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2025-11-24<\/td>\n<td>2026-05-26<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]icloud-cdn[.]net\/vshost.exe<\/td>\n<td>URL to retrieve legitimate vshost.exe binary, likely as a target for sideloading FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2026-02-04<\/td>\n<td>2026-02-13<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]google-apis[.]net<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure. Also hosts plugins for FDMTP implant.<\/td>\n<td>2026-05-14<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]google-apis[.]net\/dfsvc.exe<\/td>\n<td>URL to retrieve legitimate vshost.exe binary, likely as a target for sideloading FDMTP implant.<\/td>\n<td>2026-05-14<\/td>\n<td>2026-05-17<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]google-apis[.]net\/dfsvc.exe.config<\/td>\n<td>URL to retrieve FDMTP implant.<\/td>\n<td>2026-05-14<\/td>\n<td>2026-05-17<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]google-apis[.]net\/wangmeng.dll<\/td>\n<td>URL to retrieve updated FDMTP implant.<\/td>\n<td>2026-05-14<\/td>\n<td>2026-05-17<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]techcheck1[.]com<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure. Also hosts plugins for FDMTP implant.<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/GetPeers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/GetClusterNodes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/vshost.exe<\/td>\n<td>URL to retrieve legitimate vshost.exe binary, likely as a target for sideloading FDMTP implant.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll<\/td>\n<td>URL to retrieve loader for encrypted FDMTP payload. Aligns with behavior reported by Darktrace.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/config.etl<\/td>\n<td>URL to retrieve encrypted FDMTP payload. Aligns with behavior reported by Darktrace.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/dfsvc.exe.config<\/td>\n<td>URL to retrieve FDMTP implant.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]techcheck1[.]com\/wangmeng.dll<\/td>\n<td>URL to retrieve updated FDMTP implant.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-23<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure. Previously reported by Darktrace. Also hosts plugins for FDMTP implant.<\/td>\n<td>2026-02-09<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/dfsvc.exe.config<\/td>\n<td>URL to retrieve FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-05-28<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/dnscfg.dll<\/td>\n<td>URL to retrieve FDMTP implant. Originally reported by Darktrace.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-05-28<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/GetCluster<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-06-16<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/vshost.exe<\/td>\n<td>URL to retrieve legitimate vshost.exe binary as a target for sideloading FDMTP implant.<\/td>\n<td>2026-02-09<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/dfsvc.exe<\/td>\n<td>URL to retrieve legitimate vshost.exe binary, likely as a target for sideloading FDMTP implant.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-05-28<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll<\/td>\n<td>URL to retrieve loader for encrypted FDMTP payload. Originally reported by Darktrace.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-04-10<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]yahoo-cdn[.]it[.]com\/config.etl<\/td>\n<td>URL to retrieve encrypted FDMTP payload. Originally reported by Darktrace.<\/td>\n<td>2026-03-12<\/td>\n<td>2026-04-10<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]wangmeng[.]xyz<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetVips<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetPeers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetAgents<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetEndpoints<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetInstances<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetMachines<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetMembers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetNodes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetReplicas<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetRoutes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetServers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetTargets<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng[.]xyz\/GetWorkers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-04<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]wangmengsb[.]com<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetAddresses<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetAgents<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetBackends<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetHosts<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetServers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-08<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetIps<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetNodes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetPeers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetReplicas<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetRoutes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetVips<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmengsb[.]com\/GetWorkers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-03<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>www[.]wangmeng66[.]top<\/td>\n<td>Staging and registration domain used to provide active FDMTP implants with details of clusters forming FDMTP infrastructure.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetAddresse<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetEndpoints<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetHosts<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetInstances<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetMachines<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetPeers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetProxies<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetReplicas<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-1<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetResources<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetRoutes<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetServers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetTargets<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>www[.]wangmeng66[.]top\/GetWorkers<\/td>\n<td>Registration URL for staging domain.<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]157[.]196<\/td>\n<td>IP resolved from cdns3[.]51quickfox[.]cn . Note: Cloudflare IP<\/td>\n<td>2025-06-10<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]89[.]96<\/td>\n<td>IP resolved from cdns3[.]51quickfox[.]cn . Note: Cloudflare IP<\/td>\n<td>2025-06-10<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]76[.]92[.]73<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-11-05<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]83[.]122[.]51<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-09-25<\/td>\n<td>2025-11-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>170[.]33[.]128[.]5<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-09-02<\/td>\n<td>2025-09-25<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]86[.]14[.]22<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-06-03<\/td>\n<td>2025-08-09<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>154[.]223[.]54[.]159<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-10-23<\/td>\n<td>2025-10-27<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>154[.]223[.]24[.]158<\/td>\n<td>IP resolved from www[.]icloud-cdn[.]net<\/td>\n<td>2025-10-22<\/td>\n<td>2025-10-23<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]144[.]222<\/td>\n<td>IP resolved from www[.]google-apis[.]net. Note: Cloudflare IP<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-11<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]39[.]112<\/td>\n<td>IP resolved from www[.]google-apis[.]net. Note: Cloudflare IP<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-11<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]197[.]227<\/td>\n<td>IP resolved from www[.]techcheck1[.]com. Note: Cloudflare IP<\/td>\n<td>2026-05-26<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]44[.]82<\/td>\n<td>IP resolved from www[.]techcheck1[.]com. Note: Cloudflare IP<\/td>\n<td>2026-05-26<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]210[.]148<\/td>\n<td>IP resolved from www[.]yahoo-cdn[.]it[.]com. Note: Cloudflare IP<\/td>\n<td>2026-02-11<\/td>\n<td>2026-05-15<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]37[.]164<\/td>\n<td>IP resolved from www[.]yahoo-cdn[.]it[.]com. Note: Cloudflare IP<\/td>\n<td>2026-02-11<\/td>\n<td>2026-05-15<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]135[.]248<\/td>\n<td>IP resolved from www[.]wangmengsb[.]com. Note: Cloudflare IP<\/td>\n<td>2026-06-05<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]7[.]138<\/td>\n<td>IP resolved from www[.]wangmengsb[.]com. Note: Cloudflare IP<\/td>\n<td>2026-06-05<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>172[.]67[.]143[.]103<\/td>\n<td>IP resolved from www[.]wangmeng[.]xyz. Note: Cloudflare IP<\/td>\n<td>2026-06-17<\/td>\n<td>2026-06-17<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>104[.]21[.]95[.]64<\/td>\n<td>IP resolved from www[.]wangmeng[.]xyz. Note: Cloudflare IP<\/td>\n<td>2026-06-17<\/td>\n<td>2026-06-17<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>103[.]231[.]15[.]135<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-18<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]15[.]104<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-29<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]229<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]233<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-20<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]15[.]114<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>103[.]231[.]15[.]248<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-25<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]15[.]115<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-20<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>123[.]254[.]105[.]38<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-20<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]227<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]235<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-18<\/td>\n<td>2026-07-03<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]226<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]234<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>202[.]181[.]25[.]73<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-25<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>103[.]246[.]244[.]13<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>103[.]246[.]244[.]20<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]236<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-18<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>103[.]231[.]15[.]219<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-21<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>43[.]240[.]12[.]34<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-20<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]225<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-26<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>123[.]254[.]106[.]148<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-25<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]15[.]100<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-28<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]230<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-23<\/td>\n<td>2026-07-02<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]231<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-01<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>43[.]240[.]12[.]35<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-21<\/td>\n<td>2026-07-01<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]15[.]111<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-07-01<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]125[.]35[.]232<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-20<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>202[.]181[.]25[.]71<\/td>\n<td>IP resolved from www[.]wangmeng66[.]top<\/td>\n<td>2026-06-16<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>154[.]223[.]75[.]206<\/td>\n<td>FDMTP cluster<\/td>\n<td>2025-01-21<\/td>\n<td>2025-01-21<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>154[.]223[.]58[.]142<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-05-18<\/td>\n<td>2026-05-19<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]238[.]240[.]219<\/td>\n<td>FDMTP cluster<\/td>\n<td>2025-11-25<\/td>\n<td>2025-11-25<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>154[.]223[.]58[.]64<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-05-18<\/td>\n<td>2026-05-18<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>45[.]158[.]180[.]250<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-19<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]238[.]64[.]56<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-03-27<\/td>\n<td>2026-06-11<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]239[.]93[.]49<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-01-21<\/td>\n<td>2026-01-21<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>38[.]60[.]142[.]56<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-02-13<\/td>\n<td>2026-06-30<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]239[.]4[.]179<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-05-21<\/td>\n<td>2026-06-08<\/td>\n<\/tr>\n<tr>\n<td>IP<\/td>\n<td>47[.]88[.]21[.]252<\/td>\n<td>FDMTP cluster<\/td>\n<td>2026-05-21<\/td>\n<td>2026-05-22<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Host Based Indicators<\/h3>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"indicators-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<th width=\"15%\">Full Path<\/th>\n<th width=\"10%\">File Name<\/th>\n<th width=\"20%\">Description<\/th>\n<th width=\"15%\">MD5<\/th>\n<th width=\"15%\">SHA1<\/th>\n<th width=\"15%\">SHA256<\/th>\n<th width=\"10%\">FortiGuard AV Signature<\/th>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>Microsoft.ServiceHosting.Tools.dll<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">Microsoft.ServiceHosting.Tools.dll<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Generation 1 FDMTP loader. Self-contained FDMTP payload stored as byte array<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">3B79D95F7F7B58C401A3BC79F94EBB52<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">173DD4190740B96F6F733C801B6428ED4B52B607<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">2B6CDAFDFE427A3DE1A94A8A2CA1F09FC4C8F90E4F59089FD9B35B73185ED01C<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">MSIL\/Agent.BB52!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>Microsoft.ServiceHosting.Tools.dll<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">Microsoft.ServiceHosting.Tools.dll<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Generation 2 FDMTP loader. Obfuscated .NET module that decrypts and reflectively loads the FDMTP payload stored in collocated \u2018<i>update.bin<\/i>\u2019 file.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">03FD832B81DD54D2BF5F610A8FF27856<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">7AB7FFE4C233A4F2440F0FDEB2E117C788792281<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">795594AD5E6F2868CC4D8ED12DABF4F3999A1477C6B250527C5EDE9A98528FB9<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">MSIL\/Agent.7856!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>Microsoft.ServiceHosting.Tools.dll<i><\/i><\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">Microsoft.ServiceHosting.Tools.dll<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Generation 2 FDMTP loader. Obfuscated .NET module that decrypts and reflectively loads the FDMTP payload stored in collocated \u2018<i>config.bin<\/i>\u2019 file.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">2DD8681DCD218C88D1C78DFE939EC92B<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">C41B4E11E6A9E3B53DA1F92B213DE9F65A825C92<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">6634339B813E6105B5138DE6AB67B016B8DFBF49233C29DE9BAB3207E8B50D24<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">MSIL\/Agent.C92B!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>csmonitor.exe<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">csmonitor.exe<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Legitimate Windows binary used to sideload both generations of FDMTP loader. Not malicious.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">2FFDCFB7157511789228988E26D06FD6<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">39504CEAD410056878962053F8D027E9F299CD10<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">A5D36EDC34FE54B2092349F877DAF560A98F5FEA635D1AC4A110B3518102EF96<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Legitimate executable (not malicious)<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>update.bin<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.bin<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Encrypted FDMTP payload. Decrypted and loaded by generation 2 FDMTP loader.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">5E4ED6ABBF555E5A542E3D4308CCD7BF<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">B370B674CE877B9C0A7708C7834AEB7EDA983564<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">DC666E9C148BBCA5E21D8C9A97143575C075F53360F135E0191AED9E8278D396<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Data\/Agent.D7BF!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>update.bin<i><\/i><\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.bin<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Encrypted FDMTP payload. Decrypted and loaded by generation 2 FDMTP loader.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">19E760EE849EB7C1F100F2B7010A763D<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">3449A349B6C8045B16DF4F88D58C65C2BDF891BB<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">5CBB64375636E83B5F17D6083633CECC02E2A5F4168CD7CCA5CDEE36CCCA9B38<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Data\/Agent.763D!tr<\/p>\n<p style=\"\ttext-align: left;\n\">\u00a0<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\"><i>%APPDATA%\\Local\\Temp\\quickfox\\updated\\<\/i>config.bin<i><\/i><\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">config.bin<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Encrypted FDMTP payload. Decrypted and loaded by generation 2 FDMTP loader.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">1F3031167F94B166CC7B69376A01C124<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">B194A997C9A653134BDB1F2D0C3137DCDACB54D5<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">A53D756F28457B1C4A239C91CDEC8ED7B7DA67A93E332E6DF9621CBEF8417474<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Data\/Agent.C124!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\">&#8211;<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.zip<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Zip containing generation 1 FDMTP loader and \u2018<i>csmonitor.exe<\/i>\u2019.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">30D59C3D4916AA5FB24050C6AAE7F8E4<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">A195810C41F401C4B48CB557CF8CE60C2D807025<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">D9DB5CBC193DDAF4C0A265804FDEF70C32451DAAF2974FA9ADF52CE1DEFAC5F7<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">MSIL\/Agent.BB52!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\">&#8211;<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.zip<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Zip containing generation 2 FDMTP loader, payload and \u2018<i>csmonitor.exe<\/i>\u2019.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">E0A92209DD62DAE8460D934DC6B7DDD7<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">2CC0425A90A39AC4EEDADD59CAAAFAD5B50F8420<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">7462CE2595119C928CF516EC33148DC2A39DD9F71636A5C849C7ED93B7C5CA06<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Zip\/Agent.DDD7!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\">&#8211;<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.zip<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Zip containing generation 2 FDMTP loader, payload and \u2018<i>csmonitor.exe<\/i>\u2019.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">B1D344C9A1525373BE6A3980FA85A603<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">11A6DF1E15663AE89F59A9E598AE8987F42A632B<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">3BD3B300F3278520819A06D0CB1F0EADBF946DBBC11352538246FF075EB427F1<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Zip\/Agent.DDD7!tr<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"144\">\n<p style=\"\ttext-align: left;\n\">&#8211;<\/p>\n<\/td>\n<td valign=\"top\" width=\"96\">\n<p style=\"\ttext-align: left;\n\">update.zip<\/p>\n<\/td>\n<td valign=\"top\" width=\"204\">\n<p style=\"\ttext-align: left;\n\">Zip containing generation 2 FDMTP loader, payload and \u2018<i>csmonitor.exe<\/i>\u2019.<\/p>\n<\/td>\n<td valign=\"top\" width=\"120\">\n<p style=\"\ttext-align: left;\n\">5F3DAF7417DD666213168EB6C7453CC7<\/p>\n<\/td>\n<td valign=\"top\" width=\"168\">\n<p style=\"\ttext-align: left;\n\">E90D2730F3354FF1ADF334B03C95EAC3207D47B9<\/p>\n<\/td>\n<td valign=\"top\" width=\"156\">\n<p style=\"\ttext-align: left;\n\">6932A20AC61FD3F93D7CFEE414F6F46834068AC7C9CA011B054A6A10DC56B3D1<\/p>\n<\/td>\n<td valign=\"top\" width=\"108\">\n<p style=\"\ttext-align: left;\n\">Zip\/Agent.DDD7!tr<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p style=\"\tfont-size: 13.0px;\n\">\u00a0<\/p>\n<p style=\"\tfont-size: 13.0px;\n\"><sup>1\u00a0<\/sup>https:\/\/github.com\/dcsoft-yyf\/JIEJIE.NET<br \/>\n<sup>2\u00a0<\/sup>https:\/\/www.fortinet.com\/corporate\/about-us\/contact-us\/experienced-a-breach<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Affected Platforms: Windows Endpoints<br \/>\nImpact Parties: QuickFox Users<br \/>\nImpact: Supply chain attack resulting in the installation of an implant for persistent access.<br \/>\nSeverity Level: Medium<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10424,10378,32774],"tags":[],"class_list":["post-26144","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-security","category-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26144"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26144\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26144"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}