Threat Advisory

QuickFox VPN Supply Chain Attack

Threat: Supply Chain Attacks
Targeted Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor is behind a supply chain attack that targets users of the QuickFox application, a VPN proxy and game accelerator. The attack involves a trojanized version of the application, which downloads and executes a JavaScript-based loader that fingerprints the victim endpoint to determine if it's a valid target. The goal of the attack is to install an implant for persistent access, likely for data theft or other malicious activities. The attack primarily targets Windows users, particularly those in the gaming and Chinese-speaking communities.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor is behind a supply chain attack that targets users of the QuickFox application, a VPN proxy and game accelerator. The attack involves a trojanized version of the application, which downloads and executes a JavaScript-based loader that fingerprints the victim endpoint to determine if it's a valid target. The goal of the attack is to install an implant for persistent access, likely for data theft or other malicious activities. The attack primarily targets Windows users, particularly those in the gaming and Chinese-speaking communities.[emaillocker id="1283"]

The malware infects systems through a modified Electron renderer HTML file that downloads and executes the JavaScript loader. Once inside, the loader checks for specific process names related to gaming, development, and other personal and business functions. If the conditions are met, it downloads and installs the FDMTP implant, which is embedded within a trojanized Microsoft Azure SDK file or an encrypted payload file. The attacker maintains control through a command and control server, allowing for further malicious activities.

This threat is significant for organisations because it highlights the risks associated with supply chain attacks and the importance of monitoring third-party applications. The use of legitimate software and clever evasion techniques makes it difficult to detect and recover from this attack. Organisations should take defensive actions, such as patching vulnerable applications, monitoring for suspicious activity, and implementing endpoint protection and backups, to mitigate the risk of similar attacks. Additionally, being cautious when installing software from untrusted sources and keeping applications up-to-date can help prevent such threats.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Resource Development T1583.006 Acquire Infrastructure Web Services
Initial Access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1059.007 Command and Scripting Interpreter JavaScript
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Execution T1116 Signed Binary Proxy Execution
Defense Evasion T1027 Obfuscated Files or Information
Defense Evasion T1140 Deobfuscate/Decode Files or Information
Defense Evasion T1497.001 Virtualization/Sandbox Evasion System Checks
Discovery T1057 Process Discovery
Command and Control T1105 Ingress Tool Transfer
Command and Control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

reports contain further technical details:
https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant

[/emaillocker]
crossmenu