EXECUTIVE SUMMARY
A threat actor is behind a supply chain attack that targets users of the QuickFox application, a VPN proxy and game accelerator. The attack involves a trojanized version of the application, which downloads and executes a JavaScript-based loader that fingerprints the victim endpoint to determine if it's a valid target. The goal of the attack is to install an implant for persistent access, likely for data theft or other malicious activities. The attack primarily targets Windows users, particularly those in the gaming and Chinese-speaking communities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A threat actor is behind a supply chain attack that targets users of the QuickFox application, a VPN proxy and game accelerator. The attack involves a trojanized version of the application, which downloads and executes a JavaScript-based loader that fingerprints the victim endpoint to determine if it's a valid target. The goal of the attack is to install an implant for persistent access, likely for data theft or other malicious activities. The attack primarily targets Windows users, particularly those in the gaming and Chinese-speaking communities.[emaillocker id="1283"]
The malware infects systems through a modified Electron renderer HTML file that downloads and executes the JavaScript loader. Once inside, the loader checks for specific process names related to gaming, development, and other personal and business functions. If the conditions are met, it downloads and installs the FDMTP implant, which is embedded within a trojanized Microsoft Azure SDK file or an encrypted payload file. The attacker maintains control through a command and control server, allowing for further malicious activities.
This threat is significant for organisations because it highlights the risks associated with supply chain attacks and the importance of monitoring third-party applications. The use of legitimate software and clever evasion techniques makes it difficult to detect and recover from this attack. Organisations should take defensive actions, such as patching vulnerable applications, monitoring for suspicious activity, and implementing endpoint protection and backups, to mitigate the risk of similar attacks. Additionally, being cautious when installing software from untrusted sources and keeping applications up-to-date can help prevent such threats.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Resource Development | T1583.006 | Acquire Infrastructure | Web Services |
| Initial Access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Execution | T1116 | Signed Binary Proxy Execution | — |
| Defense Evasion | T1027 | Obfuscated Files or Information | — |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information | — |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion | System Checks |
| Discovery | T1057 | Process Discovery | — |
| Command and Control | T1105 | Ingress Tool Transfer | — |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
REFERENCES:
reports contain further technical details:
https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant