Cybersecurity researchers have identified a supply chain attack affecting QuickFox, a VPN and network acceleration tool primarily used by overseas Chinese users. The attack involved distributing a trojanized version of the application's Windows installer, which has been active since at least August 2025.
The trojanized installer delivered FDMTP, a backdoor linked to Mustang Panda, a Chinese state-sponsored threat actor. The attack specifically targeted Windows users, with the earliest affected version identified as 3.0.51.0.
The attack utilized a modified Electron renderer HTML file to download and execute a JavaScript-based loader. This loader fingerprinted the victim's endpoint to confirm it was a valid target before installing the FDMTP implant. The malicious JavaScript code mimicked Google Firebase SDK components and was hosted on a domain designed to resemble the official QuickFox domain to evade detection.
The malicious payload checked for the presence of specific processes, including Steam, and would abort execution if found. It also checked for 26 domestic applications, cryptocurrency wallets, developer tools, and enterprise software, indicating a targeted approach. This behavior suggests an attempt to avoid detection on systems not matching the attacker's intended profile.
Following responsible disclosure, QuickFox removed the malicious components from their Windows installer. The fix was included in version 3.59.6, with changes implemented between July 25 and August 13, 2025.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity researchers have uncovered a supply chain attack targeting QuickFox, a VPN service, that has been ongoing since at least August 2025. The attack involved a modified Windows installer delivering the FDMTP backdoor, attributed to the Chinese state-sponsored threat actor Mustang Panda. This incident highlights the ongoing risk of supply chain compromises, particularly for software used by specific user demographics.