Skip to main content
Mallory
MalwareUsed by 1 actor

FDMTP

FDMTP is a .NET malware downloader associated with the China-aligned espionage group Mustang Panda, also tracked as Earth Preta, Twill Typhoon, and MISTCLOAK. Earlier reporting described it as a simple malware downloader implemented on the TouchSocket library over Duplex Message Transport Protocol (DMTP), used as a secondary control tool and to perform tasks similar to PUBLOAD. Trend Micro reported PUBLOAD was used to introduce FDMTP into victim environments during Mustang Panda operations, including campaigns targeting government-related entities in Asia such as Myanmar, the Philippines, Vietnam, Singapore, Cambodia, and Taiwan.

Later reporting indicates FDMTP evolved into a more modular .NET backdoor / remote access framework. Darktrace observed a heavily obfuscated payload identified as Client.TcpDmtp.dll, communicating over custom TCP using DMTP and assessed it as an updated version of FDMTP (version 3.2.5.1). The malware was delivered via retrieval of legitimate executables together with malicious DLLs, enabling DLL sideloading and search-order hijacking. Observed legitimate binaries included biz_render.exe, dfsvc.exe, and vshost.exe; malicious components included browser_host.dll and dnscfg.dll. In one chain, a malicious dfsvc.exe.config forced loading of dnscfg.dll through a custom AppDomainManager during dfsvc.exe initialization. The malware also used staged retrieval from spoofed CDN-themed infrastructure, including yahoo-cdn.it[.]com and icloud-cdn[.]net, and registration traffic to a /GetCluster endpoint with protocol=DotNet-TcpDmtp and header Verify_Token: Dmtp.

Capabilities directly described in the reporting include host profiling, C2 communication, plugin execution, modular component loading, malware updating after deployment, and persistence through normal-looking Windows and developer-related processes. Embedded components included client.core.dll and client.dmtpframe.dll. Reported functionality included collection of host details such as antivirus products, domain name, HWID, CLR version, administrator status, hardware, network, operating system, and user information; heartbeats, reconnection, RPC-style messaging, SSL support, token verification, and plugin persistence. Plugins identified in reporting were Persist.WpTask.dll, Persist.registry.dll, Persist.extra.dll, and Assist.dll. Persistence mechanisms included a scheduled task for %APPDATA%\Local\Microsoft\WindowsApps\dfsvc.exe, registry storage of plugins under HKCU\Software\Microsoft\IME{id}, and COM-related persistence via HKCU\Software\Classes\TypeLib{9E175B61-F52A-11D8-B9A5-505054503030}\1.0\1\Win64.

Additional technical details reported for the updated framework include runtime string decryption using an XOR-based routine, cluster-based host resolution, a persistent LoopMessage routine for structured tasking, and in-memory loading of AES-encrypted payloads. One observed workflow involved checking icloud-cdn[.]net every five minutes, downloading checksum.bin when version.txt changed, saving it as C:\ProgramData\USOShared\Logs\checksum.etl, decrypting it with the hardcoded AES key POt_L[Bsh0=+@0a., and loading the resulting assembly from memory as Client.dll. Darktrace reported activity beginning in late September 2025 affecting environments in the Asia-Pacific and Japan region, including government targets and at least one finance-sector endpoint.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Mustang Panda

PUBLOAD was also used to introduce supplemental tools into the targets' environment, such as FDMTP to serve as a secondary control tool ... FDMTP, which is a "simple malware downloader" implemented based on TouchSocket over Duplex Message Transport Protocol (DMTP).

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.001DomainsEvidence1

multiple hosts began in September 2025 making requests to spoofed domains impersonating content delivery networks, including infrastructure putatively belonging to Yahoo and Apple.

Execution

1 technique
T1059.005Visual BasicEvidence1
TacticExecution

The group is known for its use of a .NET malware downloader known as FDMTP.

Stealth

1 technique
T1036MasqueradingEvidence1
TacticStealth

The backdoor now has a remote access framework that allows hackers to layer on components, load plugins, update it and maintain access through normal-looking Windows and developer-related processes.

T1071.001Web ProtocolsEvidence1

Researchers spotted the group's latest activity when multiple hosts began in September 2025 making requests to spoofed domains impersonating content delivery networks, including infrastructure putatively belonging to Yahoo and Apple.

T1105Ingress Tool TransferEvidence3

PUBLOAD is a known downloader malware ... deployed ... to deliver the PlugX malware ... PUBLOAD was also used to introduce supplemental tools into the targets' environment, such as FDMTP ...

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app22 days ago
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.