A long-standing supply chain attack on QuickFox VPN has been delivering the FDMTP backdoor via a trojanized Windows installer since August 2025. Here's what you need to know.
If you've been using QuickFox to speed up your connection or get around geo-blocks, you might want to sit down for this one. Cybersecurity researchers just uncovered what they're calling a long-standing supply chain attack on this popular VPN and network acceleration tool, which is especially favored by Chinese users living overseas. The scary part? It's been going on since at least August 2025, and nobody noticed until now.
That's a long time for a backdoor to be sitting in your system, quietly doing who knows what. And the attack isn't some random hacker working from a basement. It's a carefully orchestrated operation that involved tampering with the official installer before it ever reached users.
### What Actually Happened?
Here's the breakdown, plain and simple. Fortinet's FortiGuard Labs discovered that the QuickFox installer was trojanized. That means someone took the legitimate Windows installer, modified it, and then distributed that poisoned version as if it were the real deal. When users downloaded and ran it, they weren't just installing a VPN. They were also installing a backdoor called FDMTP.
FDMTP isn't a household name, but it doesn't need to be. It's a remote access tool that gives attackers a way in. Once it's on your machine, it can do a lot of things you definitely don't want happening, like:
- Exfiltrating sensitive files from your system
- Logging your keystrokes to capture passwords and other credentials
- Downloading and executing additional malware payloads
- Maintaining persistent access so they can come back anytime
Think of it like someone swapping the lock on your front door with one they have a key to. You think you're safe, but they can walk in whenever they want.
### Why This One Feels Different
Supply chain attacks are nothing new, but this one stands out for a few reasons. First, the sheer duration. We're talking about months of potential exposure. Second, the target audience. QuickFox is designed for overseas Chinese users, which is a specific community that often relies on this tool for a stable connection back home. That makes it a prime target for surveillance or data theft.
Third, and maybe most importantly, this attacks the trust we place in official downloads. You do everything right. You go to the official site, download the installer, and run it. And still, you get compromised. That's a tough pill to swallow.
### What Should You Do Right Now?
If you've installed QuickFox on your Windows machine recently, don't panic, but do take action. Here's a sensible checklist to work through:
- Uninstall QuickFox immediately if you don't absolutely need it
- Run a full system scan with a reputable antivirus or endpoint detection tool
- Check for any unfamiliar processes running in your Task Manager
- Change your passwords, especially for critical accounts like email and banking
- Enable multi-factor authentication wherever you can
It's also worth keeping an eye on Fortinet's advisories for more details and indicators of compromise. The more you know, the better you can protect yourself.
### The Bigger Picture
This attack is a reminder that no software is truly safe, even when it comes from a trusted source. The bad guys are getting smarter, and they're going after the supply chain because it's a way to hit thousands of people at once.
For the average user, the takeaway is simple: be cautious about what you install, keep your security tools updated, and don't assume that just because a download is official, it's safe. This QuickFox incident shows that even the most careful among us can be caught off guard.
Stay safe out there, and if you're using any VPN or acceleration tool, make sure you know exactly where it came from and what it's doing on your system.