All incidents

QuickFox VPN supply chain attack delivers FDMTP malware

malwareopenAug 5, 2026 — Aug 5, 2026

Attackers compromised the QuickFox VPN distribution channel, inserting a malicious payload that installs the FDMTP backdoor on Windows systems. The trojanized app was linked to the threat actor Twill Typhoon and remained undetected for an extended period before being uncovered by FortiGuard Labs. Affected users are advised to remove the compromised version and update to a clean build.

CyberSIXT is compiling the full intelligence briefing for this incident — gathering sources and cross-checking coverage. Check back in a few minutes.

Timeline Coverage

Swipe to explore timeline