Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

Key points
- Fortinet FortiGuard Labs disclosed a supply chain attack on QuickFox, a VPN and network acceleration tool aimed at overseas Chinese users, running since at least August 2025.
- The tampered Windows installer delivers a backdoor tracked as FDMTP, giving attackers hands-on access to infected machines.
- The tradecraft overlaps with activity Fortinet links, at medium confidence, to the China-nexus cluster commonly known as Silver Fox.
- Users who installed QuickFox in the past few months should uninstall it and run a full antivirus scan.
- The attack is a reminder that even trusted software downloads can be poisoned before they reach the user.
A popular VPN used by Chinese speakers abroad has been quietly serving a hidden backdoor to the people who installed it, according to new research from Fortinet.
The tool is called QuickFox. It is a virtual private network, meaning software that reroutes your internet traffic through another country so websites think you are somewhere else. Chinese users living overseas often use it to reach services back home that are otherwise slow or blocked.
Fortinet's FortiGuard Labs team, first reported by The Hacker News, says the QuickFox installer for Windows was tampered with somewhere in the supply chain. Anyone who downloaded it got the real app plus an unwelcome extra: a stealth program the researchers track as FDMTP.
What does the hidden program actually do?
FDMTP is a backdoor, which is a piece of malicious software that opens a secret door into your computer so attackers can come and go as they please. Once it is running, the operators can send commands, steal files, install more malware, or watch what the user is doing.
The backdoor is planted quietly during a normal-looking install. Nothing on screen tells the user anything is wrong. The VPN works as advertised, which is exactly why the trick is effective.
Who is behind it?
Fortinet has not made a firm attribution. The researchers note that the tools, the way the code is packed, and parts of the delivery chain overlap with activity previously tied to the China-nexus cluster many vendors call Silver Fox (also tracked as Void Arachne in some reporting). That is a medium-confidence link, not proof. Silver Fox has a long history of poisoning installers for Chinese-language software to reach users inside and outside the mainland.
Capability and intent are worth separating here. A group that can slip a backdoor into a VPN installer clearly has the skills for espionage. Whether this particular campaign is being used for spying on specific people, or simply casting a wide net over the Chinese-speaking diaspora, is not yet clear from the public reporting.
How long has this been going on?
Fortinet describes it as a "long-standing" campaign that has been active since at least August 2025. That means anyone who downloaded QuickFox in the past few months could be affected.
| Detail | What Fortinet says |
|---|---|
| Targeted software | QuickFox VPN and acceleration tool |
| Target users | Overseas Chinese speakers |
| Payload | FDMTP backdoor |
| Active since | At least August 2025 |
| Suspected operator | Overlaps with Silver Fox (medium confidence) |
What should users do?
If you installed QuickFox on a Windows machine at any point since the summer, uninstall it and run a full scan with a reputable antivirus product. Change passwords for any accounts you signed into from that computer, starting with email and banking. If the machine is used for work, tell your IT team.
Downloading only from official sources is the usual advice, and it still matters. But this case shows the limit of that rule. The official download itself was the problem.



