Dossier
Fortinet FortiGuard Labs
Coverage of Fortinet FortiGuard Labs in the Nexus archive.
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed a long-standing supply chain attack on QuickFox, a virtual private network (VPN) and network acceleration tool for overseas Chinese users. Fortinet FortiGuard Labs reported the attack, which has been ongoing since at least August 2025, involves a trojanized version of the application to deliver FDMTP, a backdoor.
- Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Threat actors are exploiting CVE-2024-3721, a medium-severity command injection vulnerability in TBK DVRs and end-of-life TP-Link Wi-Fi routers, to deploy the Mirai-botnet variant Nexcorium. Fortinet FortiGuard Labs and Palo Alto Networks Unit 42 have identified this attack, which hijacks devices for DDoS botnet operations.