securityonline.info 8/7/2026, 8:32:04 AM · external

Supply chain attack hijacks QuickFox, targets Chinese students

Supply chain attack hijacks QuickFox, targets Chinese students
CyberSIXT Evidence Panel
Primary Source fortinet.com

A recent security report from FortiGuard Labs reveals a supply chain attack targeting the QuickFox VPN and game accelerator, primarily affecting Windows users, particularly Chinese students abroad. The attack deploys the FDMTP implant through a trojanized QuickFox installer. It relies on a two-line JavaScript modification to an HTML file, utilizing typosquatting to redirect users to a malicious domain. The implant performs endpoint fingerprinting, collects data, and connects to command and control servers.

Affected versions of QuickFox include those between v3.0.35 and v3.55.6, with remediation underway from v3.59.6. The ongoing risk highlights the complexity of such attacks and the need for vigilance against trusted software being compromised.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline