The QuickFox VPN Supply Chain Attack
Updated 5 Oct 2026 · Incident date 1 Aug 2025 · vendor binary
QuickFox VPN/accelerator for Windows 3.0.51.0 through 3.59.5; fixed in 3.59.6index.html inside the Electron app.asar, edited to load...QuickFox for Windows, versions 3.0.51.0 through 3.59.5, shipped with injected JavaScript that loaded the FDMTP backdoor. QuickFox fixed the problem in version 3.59.6.
The Hacker News reports that the attack has run since at least August 2025. No source names the exact moment the vendor build was altered.
What happened
Attackers changed the QuickFox Windows application so that it ran a hidden loader. According to The Hacker News, they added two JavaScript lines to one HTML file in the Electron renderer. The lines loaded firebase-app-compat.js, which held the obfuscated payload, and firebase-analytics-compat.js, which was real Google Firebase code used as cover. Rescana adds that the change sat in index.html inside the app.asar archive.
The loader fingerprinted the machine. It stopped if Steam ran. It continued only if one of 26 target applications ran, such as developer tools, cryptocurrency wallets, security software and translation tools. It then downloaded ZIP archives that used DLL side-loading to start the FDMTP backdoor.
FDMTP can collect window titles, installed antivirus products, the .NET version, the operating system and the user name. It can list processes, load plugins from its server, manage scheduled tasks and registry persistence, and run files and commands. The Hacker News reports a first generation of payload from September 2025 and a second generation from May 2026.
The Hacker News reports no firm attribution. It notes tactics that overlap with Mustang Panda, and it suspects the targets are Chinese nationals abroad.
Vigilance compares the version you trust with the new one and reports the file that gained a new capability. A vendor installer that starts loading a remote script is the kind of change it shows. See the scan block below.
Affected versions
- QuickFox for Windows 3.0.51.0 through 3.59.5.
- Fixed in 3.59.6.
The Hacker News gives 3.0.51.0 as the earliest affected version. Rescana writes the range as v3.51.0 through v3.59.5. The two sources differ on the first version. Treat every build before 3.59.6 as suspect. Other platforms are not named as affected.
Indicators of compromise
- Payload domain (The Hacker News):
cdns3.51quickfox[.]cn. It imitates the real51quickfox.comname. - Other domains (Rescana):
icloud-cdn[.]net,google-apis[.]net,techcheck1[.]com,yahoo-cdn[.]it[.]com,wangmeng[.]xyz,wangmengsb[.]com,wangmeng66[.]top. - Command IP addresses (Rescana): 47.238.64.56, 47.239.93.49, 47.239.4.179, 47.88.21.252, 47.238.240.219, 154.223.75.206, 154.223.58.64, 45.158.180.250, 154.223.58.142, 38.60.142.56.
- File (Rescana):
%APPDATA%\Local\Temp\quickfox\updated\Microsoft.ServiceHosting.Tools.dll. - Loader side-loaded through a Microsoft binary,
csmonitor.exe(Rescana), with FDMTP traffic on ports 20800 to 20816. - Payload files:
Client.dll(first generation) and an encryptedupdate.bin(second generation).
How to check
Read the installed version and look for the loader in the app archive and the dropped files. This PowerShell command lists the temp folder and searches DNS cache entries for the payload domain.
Get-ChildItem "$env:LOCALAPPDATA\Temp\quickfox" -Recurse -ErrorAction SilentlyContinue; Get-DnsClientCache | Where-Object Entry -like "*51quickfox.cn*"
Check the QuickFox version in Settings, Apps, Installed apps. Any version below 3.59.6 needs action. Also search proxy logs for the domains above.
What to do now
- Update QuickFox to 3.59.6 or later, or remove it.
- Block the domains and IP addresses above.
- Search machines for the DLL and temp folder named above.
- If you find a sign of FDMTP, isolate the host and run a forensic review. Reinstall it when the review ends.
- Change passwords and wallet keys that were used on the machine, from a clean device.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 80 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED app.asar It now downloads from the internet, runs other programs and runs a hidden, encoded command. It did not before.
Frequently asked questions
Which versions of QuickFox are affected by the supply chain attack?
The Hacker News lists QuickFox for Windows 3.0.51.0 through 3.59.5. Version 3.59.6 contains the fix.
What is the FDMTP backdoor?
FDMTP is a backdoor that collects system data, loads plugins from a server and runs remote commands. In this attack, the injected QuickFox loader downloads it by DLL side-loading.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.