Only one outlet has reported this event so far — you're reading it below, credited to its source. AIPROPX is tracking the web for more coverage; as additional outlets confirm it, this becomes a full multi-source story automatically.
By AIPROPX Editorial Desk · Published · Updated
One outlet is reporting this so far. AIPROPX is tracking it and will gather every additional source as it develops — the full multi-source comparison appears automatically once a second outlet confirms it.

Fortinet experts found malicious code in QuickFox VPN's Windows installer
The attack actively avoided personal gaming computers
QuickFox has since removed the malicious components from version 3.59.6
Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese Windows VPN application.
According to a new report from Fortinet’s FortiGuard Labs , attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.
As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience . "
However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted malware campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript.
To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6.
TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.
A highly targeted backdoor
(Image credit: QuickFox)
The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers.
If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.
However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.
When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including IP addresses , active processes, MAC addresses, and usernames.
Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.
While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.
How to stay safe
While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.
The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.
If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system.
Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.
Indexed and credited by AIPROPX. Originating outlet: TechRadar. Open at source →
An original, deterministic readout — composed only from the computed coverage facts on this page. No interpretation, no rating; figures only.
AIPROPX has consolidated 1 report from 1 outlet into a single canonical entry on “Hackers caught hijacking this Chinese Windows VPN's installers to spread malware.” Every covered outlet is based in Other.
The only timestamped report came from TechRadar (Aug 6, 2026, 15:19 UTC).
2 statements are carried by only one outlet within this set and are not echoed by the others.
Every figure above is a direct count of real published articles. AIPROPX indexes and compares the original reporting — it never rewrites, rates, or editorializes — and each publisher’s full article is always one click away.
Generated by AIPROPX from the source counts above. AIPROPX indexes and resolves coverage; the original publishers are credited and linked at origin in every report.
Coverage from 1 independent outlet across 1 region — each view opens on its own page.
AIPROPX — “Hackers caught hijacking this Chinese Windows VPN's installers to spread malware” · https://www.aipropx.com/story/38296a5e6edca4f9bfca87f1c04113e0
Other events being covered across multiple sources right now.
Hackers targeted water systems in seven US states. Here’s how they tried to take control
28 outletsSenate Panel Votes to Hold Fauci in Contempt of Congress
28 outletsOh What a Night: Hamilton’s National Night Out Celebration
25 outletsThis Morning’s Top Headlines – Aug. 6
20 outletsInvestors Title: Q2 Earnings Snapshot
17 outletsIran says Hormuz deal is close. What would seal the deal?