There’s a hidden passenger in this shortcut. 🦊⚠️
Our team uncovered a long-running supply chain attack that used a trojanized #QuickFox application to identify select Windows targets and deploy the FDMTP implant for persistent access.
🔗 See how the campaign operated:
- TOMORROW: Black Hat 2026 is on! 🎰 Join #FortiGuardLabs in Las Vegas for a look at what threat intelligence is seeing next as AI-enabled adversaries raise the stakes for defenders. 🗓️ August 4-6, 2026 🔗 Get connected today: ow.ly/SaoE50ZvXiT #BHUSA
- TrickBot is changing how it hides in plain sight. 🕵️♂️ 🌐 Our team examines a variant that replaces traditional HTTP-based command-and-control with DNS tunneling, embedding encrypted data inside malformed DNS traffic. See how it maintains persistence, evades analysis, and
- A .ttf file may not be a font at all. ⌨️ 🔍 A large-scale campaign is disguising low-detection Lua loaders as font files to deploy RATs and infostealers, including Agent Tesla, Remcos, XWorm, and Snake Keylogger. See how the infection chain works and how attackers are evolving
- The next wave of AI threats is already taking shape. Join #FortiGuardLabs at Black Hat 2026 for a look at what threat intelligence is seeing next, from AI-enabled adversaries to the rise of autonomous defense. 🎤 Speaker: Aamir Lakhani, Sr. Director, AI and Threat Research 🗓️


