Skip to content
Breaking:

Hackers Compromise QuickFox VPN Installers to Distribute Malware

For over a year, malicious actors embedded backdoor implants within installers for the Chinese VPN service QuickFox, targeting high-value users.

By The Company Wire2 min read
Share
QuickFox — Hackers Compromise QuickFox VPN Installers to Distribute Malware
QuickFox — Hackers Compromise QuickFox VPN Installers to Distribute Malware. Illustration of a computer user.

Attackers successfully integrated malicious backdoor implants into the software installers of QuickFox, a VPN and game accelerator primarily used by Chinese individuals. This compromise enabled the silent deployment of malware onto users' machines for more than a year, as detailed in a recent report by Fortinet’s FortiGuard Labs.

QuickFox, known for enhancing access to Chinese resources and improving online gaming experiences, had its underlying application code manipulated by the threat actors. This modification facilitated a highly targeted malware distribution campaign. An HTML file within the application's installer was altered to automatically download and execute malicious JavaScript.

To avoid detection, the malicious code was retrieved from a fabricated domain specifically designed to mimic QuickFox’s legitimate infrastructure. Fortinet's analysis indicates that this campaign began at least by August 2025. QuickFox subsequently addressed the vulnerability, removing the malicious code in version 3.59.6 of its software.

The malware's distribution was selective, not impacting every user who downloaded the compromised VPN software. The malicious script employed conditional checks, immediately ceasing the infection process if it detected Steam, a popular online gaming platform, on a user’s device. This suggested an intent to bypass personal gaming computers.

Conversely, if the script identified tools commonly used by developers, IT administrators, or cryptocurrency users—such as Visual Studio Code, Telegram, or various cryptocurrency wallets—it proceeded with the attack. This behavior implies that the hackers were specifically seeking to compromise high-value corporate environments and professional users, rather than casual gamers.

Upon identifying a suitable target, the script leveraged a legitimate Microsoft utility to covertly install the FDMTP implant and inject the malware. This persistent backdoor granted attackers the ability to collect sensitive system data, including IP addresses, active processes, MAC addresses, and usernames.

The modular design of FDMTP also allowed the hackers to remotely download and execute additional malicious plugins, thereby securing long-term access to the compromised systems. While macOS builds contained the modified file, the infection process was exclusively carried out on Windows endpoints; Android and iOS applications remained unaffected.

Fortinet researchers have not definitively linked the attack to a specific group, though they have noted significant technical commonalities with Twill Typhoon, a recognized threat actor. The threat is now reportedly contained, with QuickFox having removed the malicious components from its Windows installer beginning with version 3.59.6, following a responsible disclosure.

Users who have utilized QuickFox on a Windows machine within the last year are advised to update their software to the latest version directly from the vendor and perform a comprehensive antivirus scan on their systems. Organizations are also encouraged to monitor their networks for any unusual activity or unauthorized file transfers originating from QuickFox installations.

Sources

  1. TechRadar report

Company: QuickFox

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.