FDMTP is a Windows-focused .NET malware family associated with Mustang Panda, also tracked as Earth Preta and Twill Typhoon. Initially described as a simple downloader built on the TouchSocket implementation of Duplex Message Transport Protocol (DMTP), it has evolved into a modular backdoor and remote access framework used in targeted espionage operations. Reported activity places it in campaigns against government-related entities in the Asia-Pacific region and in a later software supply-chain compromise affecting the QuickFox Windows application, a VPN and network acceleration tool popular with overseas Chinese users.
FDMTP has been delivered as a secondary tool by PUBLOAD and also through trojanized QuickFox installers. In the QuickFox intrusion chain, attackers modified an Electron-rendered HTML component to fetch an obfuscated JavaScript loader that profiled the host and selectively deployed the implant only on systems matching attacker-defined criteria. Later stages used DLL sideloading with legitimate Windows or developer-related executables to launch either an embedded FDMTP payload or a loader that decrypted and executed the implant. Separate observations also show the malware being staged through sideloading chains involving legitimate binaries and malicious .NET components, reflecting an emphasis on blending into normal Windows and developer tooling.
The malware performs host profiling and victim validation before or immediately after activation. Observed collection includes operating system and network details, username, process information, active window title, installed antivirus products, .NET runtime information, and other host metadata used for operator decision-making. FDMTP communicates with command-and-control infrastructure over custom TCP using DMTP, supports implant registration and cluster-based node discovery, and can receive structured tasking from the server.
More recent variants support plugin-style extensibility, allowing operators to update functionality after deployment and maintain long-term access. Reported plugin-enabled capabilities include scheduled task management, Registry-based persistence, remote retrieval of files or commands, and execution of additional modules. The malware has also been observed using encrypted or obfuscated configuration and runtime string decryption for defense evasion. Across reporting, FDMTP is consistently characterized as part of a broader Chinese state-aligned cyber-espionage toolkit emphasizing selective targeting, modular post-compromise access, and stealthy execution through legitimate-looking processes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FDMTP is a newly found hacktool used by Earth Preta. It is a simple malware downloader implemented based on TouchSocket over Duplex Message Transport Protocol (DMTP).
21 distinct techniques documented for this family, organized by ATT&CK tactic.
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP
The malware can also manage scheduled tasks and Registry persistence.
Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access.
The group is known for its use of a .NET malware downloader known as FDMTP.
The attack begins with a modified Electron renderer HTML file that downloads and executes a JavaScript loader.
Those lines pulled script files from cdns3[.]51quickfox[.]cn , a domain that resembles QuickFox infrastructure but is not the official 51quickfox[.]com domain.
FDMTP gathers system information, including active programs
FDMTP gathers system information, including active programs, antivirus software, and network details
FDMTP gathers system information, including active programs, antivirus software, and network details
The JavaScript checked that the endpoint was Windows, queried command output such as process listings, and used guardrails before the later stages downloaded and ran the implant.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor delivered via trojanized QuickFox Windows installers in a software supply-chain compromise. It is selectively deployed after system fingerprinting, suggesting a targeted espionage-oriented operation that enables victim profiling and post-compromise access.
A backdoor delivered via a trojanized QuickFox Windows installer. After target validation by a JavaScript loader, it is deployed using DLL side-loading from a ZIP archive. It collects system information such as active programs, antivirus software, and network details, exfiltrates the data to a command-and-control server, and can manage scheduled tasks and Registry persistence.
A backdoor/implant delivered via a trojanized QuickFox Windows installer. The infection chain used modified Electron-loaded HTML and downloaded JavaScript to profile Windows systems, then later loaders sideloaded the implant using csmonitor.exe and a malicious Microsoft.ServiceHosting.Tools.dll. The implant registered the endpoint with staging infrastructure, received cluster nodes, and supported plugin-style modules for remote operations and persistent access.
An implant delivered via a trojanized QuickFox installer in a supply-chain attack. It is deployed after a JavaScript-based loader fingerprints the victim system and confirms it is a valid target.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.