
QuickFox VPN installed a persistent backdoor on selected Windows computers, focusing on systems belonging to developers, administrators, translators, and cryptocurrency users.
The attack was uncovered by Fortinet’s FortiGuard Incident Response Team while investigating modified QuickFox installers and related command-and-control infrastructure. Researchers traced the compromise to two malicious lines added to an HTML file loaded when the Electron-based QuickFox application started.
Those additions instructed the software to download JavaScript from cdns3[.]51quickfox[.]cn, a domain designed to resemble QuickFox’s legitimate 51quickfox[.]com infrastructure. Fortinet said the fake domain was registered in June 2025 and is not operated by QuickFox.
QuickFox is a VPN proxy and gaming acceleration service primarily used by Chinese students and expatriates outside China. It is intended to improve access to services hosted in China, including online games and video platforms.
Fortinet found that malicious components were introduced into Windows installers sometime between July 25 and August 13, 2025. The earliest compromised build obtained by researchers was version 3.0.51.0. Some macOS packages also contained the modified file, but the attack code was configured to continue only on Windows.

Before installing the final payload, the malicious script examined the victim’s running programs. It stopped immediately when it detected steam.exe, which researchers believe was an attempt to avoid personal gaming computers.
The malware proceeded only when it found at least one application associated with business or technical work. The monitored programs included remote administration tools such as Xshell and MobaXterm, development software including Visual Studio Code and IntelliJ IDEA, database clients, cryptocurrency wallets, Telegram, and several Chinese translation utilities.
This filtering suggests the attackers were more interested in corporate or professional systems than ordinary home users, although Fortinet said the available evidence does not reveal the campaign’s precise targets.
On selected computers, the script downloaded an archive named update.zip and launched a legitimate Microsoft utility called csmonitor.exe. The attackers abused this trusted program to load a malicious file named Microsoft.ServiceHosting.Tools.dll, which then installed the FDMTP implant.
Once active, FDMTP connected to attacker-controlled servers and collected basic system information, including the Windows version, username, network configuration, installed antivirus products, active window title, and running processes. The implant could also receive additional plug-ins, store them in the Windows registry, download files, and execute programs remotely.
Fortinet said it did not observe extensive follow-on activity on the affected systems it examined. However, the implant’s modular design could provide attackers with long-term access and allow them to deploy additional tools later.

Fortinet
The researchers did not formally attribute the campaign to a specific group. They nevertheless identified strong technical overlap with operations previously associated with Twill Typhoon, including the same FDMTP malware, similar DLL sideloading methods, and shared command-and-control infrastructure.
QuickFox removed the reported malicious components after Fortinet notified the company and began an internal investigation. Fortinet said the cleaned Windows installer was released as version 3.59.6.
QuickFox users should install the latest available version directly from the vendor, remove older installations, and run a full endpoint security scan. Organizations should also review systems that used affected releases for unusual QuickFox child processes, connections to unfamiliar domains, and files such as csmonitor.exe, Microsoft.ServiceHosting.Tools.dll, update.bin, or data.dat in temporary directories.







Leave a Reply