Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

Key points
- Fortinet FortiGuard Labs disclosed a supply chain attack on QuickFox, a VPN and network acceleration tool aimed at overseas Chinese users, running since at least August 2025.
- The tampered Windows installer delivers a backdoor tracked as FDMTP, giving attackers hands-on access to infected machines.
- Tradecraft overlaps with what Fortinet links, at medium confidence, to the China-nexus cluster commonly known as Silver Fox.
- Users who installed QuickFox in the past few months should uninstall it and run a full antivirus scan.
- Downloading from an official source didn't protect anyone here: the installer itself was the poisoned link.
A popular VPN used by Chinese speakers abroad has been quietly serving a hidden backdoor to people who installed it, according to new research from Fortinet.
The tool is called QuickFox. It's a virtual private network, meaning software that reroutes your internet traffic through another country so websites think you're somewhere else. Chinese users living overseas often use it to reach services back home that are otherwise slow or blocked.
Fortinet's FortiGuard Labs team, first reported by The Hacker News, says the QuickFox installer for Windows was tampered with somewhere in the supply chain. Anyone who downloaded it got the real app plus an unwelcome extra: a stealth program the researchers track as FDMTP.
What does the hidden program actually do?
FDMTP is a backdoor, a piece of malicious software that opens a secret door into your computer so attackers can come and go as they please. Once running, operators can issue commands, exfiltrate files or drop additional payloads. Nothing on screen tells the user anything is wrong. The VPN works as advertised, which is exactly why the trick holds up.
Who is behind it?
Fortinet hasn't made a firm attribution. The researchers note that the tools, the packing methods and parts of the delivery chain overlap with activity previously tied to the China-nexus cluster many vendors call Silver Fox, also tracked as Void Arachne. That's a medium-confidence link, not proof.
This is the fourth Silver Fox story we've reported since first covering the group on 10 July 2026, and a pattern is forming: booby-trapped installers aimed at Chinese-language software users keep appearing in this cluster's playbook. The July story found Silver Fox hiding a remote-control trojan inside fake software downloads; the follow-up on 30 July showed the group abusing legitimate Windows drivers to blind security tools before dropping a remote-access trojan on Japanese industrial targets. Whether this QuickFox campaign is targeted espionage or a wide net cast over the Chinese-speaking diaspora isn't yet clear from the public reporting.
How long has this been going on?
Fortinet describes it as a "long-standing" campaign active since at least August 2025. That's a long runway before public disclosure, and anyone who downloaded QuickFox in the past year could be affected.
| Detail | What Fortinet says |
|---|---|
| Targeted software | QuickFox VPN and acceleration tool |
| Target users | Overseas Chinese speakers |
| Payload | FDMTP backdoor |
| Active since | At least August 2025 |
| Suspected operator | Overlaps with Silver Fox (medium confidence) |
What should users do?
If you installed QuickFox on a Windows machine any time since last summer, uninstall it and run a full scan with a reputable antivirus product. Change passwords for accounts you accessed from that machine, with email and financial accounts first. If the machine is used for work, tell your IT team before doing anything else.
The usual advice is to download only from official sources. It still matters. But this case shows its hard limit: the official installer was the problem.



