Skip to content
Suspected Chinese Hackers Compromised This VPN to Deliver Malware

Suspected Chinese Hackers Compromised This VPN to Deliver Malware

Uk.Pcmag August 6, 2026

A VPN program from China was secretly tampered with to deliver malware to unsuspecting users, according to researchers at cybersecurity vendor Fortinet. The attack targeted Windows installations for QuickFox VPN. Fortinet suspects a state- Chinese hacking group called Mustang Panda (aka Twill Typhoon) is behind it. Researchers uncovered the threat in malicious JavaScript within an "embedded Electron renderer HTML file bundled" into the legitimate QuickFox app. Once it executes, the JavaScript fingerprints the victim’s computer to determine if it’s a “valid target” before downloading and installing a backdoor capable of spying on a PC and downloading additional files. It's unclear how QuickFox was compromised. But the attackers added two lines of JavaScript code that will secretly fetch and execute two files from a hacker-controlled lookalike domain registered in June 2025. Affected software versions range from 3.51.0 to 3.55.5, which Fortinet says were first observed in August 2025. “QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack,” the report says. The latest version, 3.59.6, removed the malicious component. Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

The attack targeted Windows installations for QuickFox VPN. Fortinet suspects a state- Chinese hacking group called Mustang Panda (aka Twill Typhoon) is behind it. Researchers uncovered the threat in malicious JavaScript within an "embedded Electron renderer HTML file bundled" into the legitimate QuickFox app. Once it executes, the JavaScript fingerprints the victim’s computer to determine if it’s a “valid target” before downloading and installing a backdoor capable of spying on a PC and downloading additional files. It's unclear how QuickFox was compromised. But the attackers added two lines of JavaScript code that will secretly fetch and execute two files from a hacker-controlled lookalike domain registered in June 2025. Affected software versions range from 3.51.0 to 3.55.5, which Fortinet says were first observed in August 2025. “QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack,” the report says. The latest version, 3.59.6, removed the malicious component. Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

Researchers uncovered the threat in malicious JavaScript within an "embedded Electron renderer HTML file bundled" into the legitimate QuickFox app. Once it executes, the JavaScript fingerprints the victim’s computer to determine if it’s a “valid target” before downloading and installing a backdoor capable of spying on a PC and downloading additional files. It's unclear how QuickFox was compromised. But the attackers added two lines of JavaScript code that will secretly fetch and execute two files from a hacker-controlled lookalike domain registered in June 2025. Affected software versions range from 3.51.0 to 3.55.5, which Fortinet says were first observed in August 2025. “QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack,” the report says. The latest version, 3.59.6, removed the malicious component. Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

It's unclear how QuickFox was compromised. But the attackers added two lines of JavaScript code that will secretly fetch and execute two files from a hacker-controlled lookalike domain registered in June 2025. Affected software versions range from 3.51.0 to 3.55.5, which Fortinet says were first observed in August 2025. “QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack,” the report says. The latest version, 3.59.6, removed the malicious component. Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

QuickFox responded quickly to identify the trojanized components of their software, has since removed the reported components, and begun an internal investigation into the associated supply chain attack,” the report says. The latest version, 3.59.6, removed the malicious component. Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

Still, Fortinet warns the malware appears to be part of a longstanding campaign because the “infrastructure continues to be active at the time of publishing.” The backdoor communicated with hacker-controlled domains that were active since at least June 30, 2026. It suspects Mustang Panda because the compromise used domains linked to earlier hacks from that group. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer. “Behavior indicative of these initial infection stages was not observed in iOS and Android versions of the application, indicating the campaign was likely specifically targeting Windows users,” the company added. QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

QuickFox is primarily marketed to Chinese users abroad, including overseas students, providing them with a way to access local China-based services from abroad. QuickFox didn’t immediately respond to a request for .

Extracted Entities