Supply Chain Attack Hits QuickFox VPN Users with Hidden Backdoor
Security researchers at Fortinet FortiGuard Labs have uncovered a long-running supply chain attack targeting QuickFox, a VPN and network acceleration application. The attackers compromised the software's distribution process, embedding malicious code into the official Windows installer. Once installed, the trojanized version quietly deploys a backdoor known as FDMTP, giving attackers a foothold on infected systems without the user's knowledge.
Supply chain attacks like this are especially dangerous because they exploit trust — users believe they are downloading legitimate software from a known provider, when in fact the installer has been tampered with somewhere along the distribution chain. This type of attack can affect large numbers of users before it is even detected, as appears to be the case here, with the compromise reportedly active since at least August 2025.
While this particular campaign has targeted a VPN tool used primarily by overseas Chinese communities, the underlying technique — corrupting trusted software at the source — is a growing risk for businesses everywhere. Any organisation that relies on third-party software, especially tools downloaded directly from vendor websites, should be alert to the possibility that even legitimate-looking installers can carry hidden threats.