QuickFox VPN supply-chain attack used trojanized installer to infect Windows users with FDMTP malware

A supply-chain attack on QuickFox VPN and its game-accelerator app caused some Windows users to receive a malicious installer instead of legitimate software. Fortinet said a trojanized Electron installer ran a JavaScript loader that avoided many Steam users and preferentially targeted systems with development, database, or cryptocurrency tools before fetching the FDMTP implant. QuickFox has removed the malicious components.
Why it matters: People who installed QuickFox on Windows may have unknowingly infected their computers with malware. Users and organizations should treat affected installs as compromised, remove the software, hunt for persistence and credential theft, and reinstall only from a verified clean source.

Sources

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
SecurityWeek News 2026.08.07 100% relevant
This article establishes a concrete new supply-chain compromise affecting QuickFox software distribution and describes the malware behavior and victim-selection logic.
← Back to all stories