QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
ID: e7ce51af-9f40-5391-8ef6-3bf72b4f872b
STIX ID: report--e7ce51af-9f40-5391-8ef6-3bf72b4f872b
Feed Name: Fortinet Blog
Threat Score
This IOC-focused report documents an active supply-chain campaign that abused a QuickFox installer to deploy the FDMTP implant family, listing malicious and staging domains, URLs for loaders and encrypted payloads, sideloading targets, resolved IPs (including Cloudflare proxied addresses), and observed timestamps from 2025–2026; several items align with prior Darktrace reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
