Urgent.News

What's breaking now, across thousands of outlets.

Tech

Hackers caught hijacking this Chinese Windows VPN's installers to spread malware

QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for over a year to deploy a persistent backdoor.

Hackers caught hijacking this Chinese Windows VPN's installers to spread malware

A severe supply chain attack has been uncovered, targeting a popular Chinese Windows VPN application named QuickFox. Experts from Fortinet's FortiGuard Labs discovered that attackers had compromised the software's installers for over a year, using the compromised installers to covertly deploy malicious backdoor implants onto users' machines. QuickFox is a VPN proxy and game accelerator typically used by Chinese users to improve access to Chinese-based resources, which often enhances video game user experience.

The malicious actors modified an HTML file within the app's installer, which executed malicious JavaScript from a fake domain designed to mimic QuickFox's legitimate infrastructure. The malicious code was activated only in certain scenarios, targeting high-value corporate environments and professionals rather than casual gamers.

If the malicious script detected Steam running on the victim's device, it stopped the infection process. However, if it found developer tools like Visual Studio Code, Telegram, or cryptocurrency wallets, it proceeded with the attack.

The attackers used a legitimate Microsoft utility to secretly install an FDMTP implant and inject the malware into suitable targets' systems, enabling them to collect sensitive system information, such as IP addresses, active processes, MAC addresses, and usernames. FDMTP also allowed remote downloads and execution of additional malicious plugins, providing hackers with long-term access to compromised machines.

Although macOS builds contained the modified file, the infection only affected Windows endpoints. Android and iOS apps were not affected by the malware. Fortinet has not independently verified these findings, but they have reached out to QuickFox for comment. After responsible disclosure, QuickFox removed the malicious components from their Windows installer, version 3.59.6.

Users who have used QuickFox on Windows machines over the last year should update to the latest version directly from the vendor and run a full antivirus scan on their systems. Organizations are advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

BMW Has Put a Spider-Man Ad on the Dashboard Display of Owners’ Cars

James Hibberd, The Hollywood Reporter: BMW owners are taking to social media to express outrage that the automaker suddenly started pushing ads for Spider-Man: Brand New Day onto their dashboards.

  • BMW owners face Spider-Man ads on dashboard displays.
  • Promotion runs until August 10, partnership between BMW, Sony, Marvel.
  • Critics call ads intrusive, question ethics of marketing luxury cars.

More from Thursday 6 August →