Threat Intelligence

Supply Chain Attack Hits QuickFox VPN Users with Hidden Backdoor

The Hacker News · 5 Aug 2026
Key Takeaway Verify software downloads through official checksums or vendor-verified channels, and monitor endpoints for unusual behaviour even after installing trusted applications.

Security researchers at Fortinet FortiGuard Labs have uncovered a long-running supply chain attack targeting QuickFox, a VPN and network acceleration application. The attackers compromised the software's distribution process, embedding malicious code into the official Windows installer. Once installed, the trojanized version quietly deploys a backdoor known as FDMTP, giving attackers a foothold on infected systems without the user's knowledge.

Supply chain attacks like this are especially dangerous because they exploit trust — users believe they are downloading legitimate software from a known provider, when in fact the installer has been tampered with somewhere along the distribution chain. This type of attack can affect large numbers of users before it is even detected, as appears to be the case here, with the compromise reportedly active since at least August 2025.

While this particular campaign has targeted a VPN tool used primarily by overseas Chinese communities, the underlying technique — corrupting trusted software at the source — is a growing risk for businesses everywhere. Any organisation that relies on third-party software, especially tools downloaded directly from vendor websites, should be alert to the possibility that even legitimate-looking installers can carry hidden threats.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.