• Hackers caught hijacking this Chinese Windows VPN's installers to

    From TechnologyDaily@1337:1/100 to All on Thu Aug 6 16:30:22 2026
    Hackers caught hijacking this Chinese Windows VPN's installers to spread malware

    Date:
    Thu, 06 Aug 2026 15:19:54 +0000

    Description:
    QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for over a year to deploy a persistent backdoor.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Fortinet experts found
    malicious code in QuickFox VPN's Windows installer The attack actively
    avoided personal gaming computers QuickFox has since removed the malicious components from version 3.59.6 Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese Windows VPN application.

    According to a new report from Fortinets FortiGuard Labs , attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines. As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience . "

    However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted malware campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript.

    To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFoxs legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6. You may like Fake X-VPN installers found to spread credential-stealing malware here's how to stay safe Hundreds of GitHub repos found posing as real software to push malware Iran-linked group caught hiding surveillance tools in fake apps

    TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we
    receive a reply. A highly targeted backdoor (Image credit: QuickFox) The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers.

    If the malicious script detected Steam the popular distribution service for online games running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.

    However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.

    When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system
    information, including IP addresses , active processes, MAC addresses, and usernames. What to read next Hackers are hijacking legitimate news websites and reviews to drum up publicity Top download manager JDownloader hacked installers replaced with dangerous malware Check Point says VPN attacks
    caused by Qilin ransomware group

    Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.

    While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected. How to stay safe While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.

    The good news is that the threat now appears to be contained. According to
    the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.

    If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system.

    Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations. Today's best Windows VPN deals NordVPN 2 Year 2.59 /mth View
    +3 months free Surfshark 24 Months 1.79 /mth View ExpressVPN 24 month 1.99 /mth View Proton VPN 24 Month 2.39 /mth View We check over 250 million products every day for the best prices Follow TechRadar on Google News and
    add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!



    ======================================================================
    Link to news story: https://www.techradar.com/vpn/vpn-privacy-security/hackers-caught-hijacking-th is-chinese-windows-vpns-installers-to-spread-malware


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)