A popular Windows VPN and proxy tool spent more than a year quietly installing a backdoor alongside its legitimate software, and almost nobody noticed. Security researchers disclosed on August 5, 2026, that QuickFox, a VPN and game-acceleration tool widely used by Chinese users to reach Chinese-based services and speed up regional connections, had its official installer trojanized to deploy a persistent backdoor tracked as FDMTP.

What happened

According to reporting from The Hacker News, attackers modified an HTML file embedded within QuickFox’s legitimate installer to automatically download and execute malicious JavaScript from a fake domain registered specifically to mimic QuickFox’s real infrastructure. The campaign had reportedly been active since at least August 2025, meaning the compromised installer was distributed to unknown numbers of users for roughly a year before discovery.

QuickFox removed the malicious code in version 3.59.6 of its software. The infection mechanism only executed on Windows; while macOS builds reportedly contained the modified file as well, the malicious payload didn’t activate on that platform, and Android and iOS apps were unaffected entirely.

What the backdoor actually did

The FDMTP backdoor, once installed, collected sensitive system information including IP addresses, running processes, MAC addresses, and usernames from infected machines. Because FDMTP is modular, it also let attackers remotely download and execute additional malicious plugins, giving them ongoing, flexible access to compromised systems well beyond initial data collection.

Security researchers have attributed the backdoor’s use to Mustang Panda, a threat actor widely tracked as linked to Chinese state-sponsored espionage operations. That attribution, combined with the targeting of a tool specifically popular among Chinese-speaking users, points toward a campaign more focused on intelligence gathering against specific user populations than opportunistic, broad-based cybercrime.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Timeline of the campaign

August 2025: Attackers begin distributing the trojanized QuickFox installer, embedding malicious code that downloads and executes JavaScript from a lookalike domain. Roughly one year of undetected distribution follows. Version 3.59.6: QuickFox removes the malicious installer code, though the exact internal trigger for this fix relative to the public disclosure timeline hasn’t been detailed publicly. August 5, 2026: Security researchers publicly disclose the campaign and attribute the FDMTP backdoor’s deployment to Mustang Panda.

Why this matters beyond QuickFox specifically

This incident is a clean, current example of a risk that applies well beyond one obscure regional tool: the software supply chain for VPN and proxy tools is an attractive target precisely because users install this kind of software expecting it to protect them, which makes a compromised installer especially damaging to trust once discovered. A backdoor delivered through a VPN’s own installer bypasses most of the caution users would normally apply to unsolicited downloads or phishing links, since the app itself is the thing they intentionally sought out and trusted.

It’s also a reminder that “VPN” and “proxy” tools popular in specific regional markets, often outside the mainstream providers covered in most Western VPN comparisons, carry real, sometimes elevated risk. QuickFox isn’t a fringe app; it has a substantial user base specifically because it solves a real regional connectivity problem, which is exactly what made it a useful vector for a targeted campaign.

How supply chain attacks like this typically get discovered

FDMTP wasn’t caught through a routine QuickFox security review; it surfaced through independent security researchers analyzing installer behavior and network traffic patterns, the same kind of external scrutiny that regularly turns up issues in far larger, more established software products. This is worth understanding because it cuts both ways: the fact that outside researchers eventually found and disclosed this campaign is a reasonably functioning part of the security ecosystem working as intended, even though it took roughly a year to happen. A tool with more consistent, ongoing independent auditing, the kind mainstream VPN providers increasingly commission proactively, gives that same kind of scrutiny a better chance of catching a compromise faster, rather than relying on researchers stumbling onto it after the fact.

How to check if you’re affected

If you have QuickFox installed, verify you’re running version 3.59.6 or later, which removed the malicious installer code. If you installed or reinstalled QuickFox at any point between August 2025 and the August 2026 disclosure, consider your system potentially exposed: check for unfamiliar running processes, review any unexpected outbound network connections, and consider a full malware scan with an updated, reputable security tool. Given FDMTP’s modular design, a basic uninstall of QuickFox alone does not guarantee removal of anything the backdoor separately downloaded and installed.

Get NordVPN

How this fits the wider pattern of VPN and proxy tool risk

QuickFox joins a growing list of incidents this year showing that VPN and proxy trust is a function of what’s independently verified, not what’s advertised. Our coverage of the SplitVPN breach showed a “no-logs” provider that had actually been logging tens of millions of connections. Our coverage of Operation Saffron showed a VPN service seized after being used to facilitate ransomware operations. QuickFox adds a third pattern to the list: a legitimate, widely used tool compromised at the distribution level by a sophisticated, patient attacker willing to wait a year for the campaign to be discovered.

None of these three incidents involve the same failure. One is a false privacy claim, one is a service built for malicious use from the start, and one is a trusted tool compromised from outside. Taken together, they argue for the same practical response: prioritize providers with active, ongoing independent security scrutiny (audits, bug bounties, public vulnerability disclosure programs) over providers, however popular regionally, that operate with minimal external review.

The broader lesson on choosing a VPN

Stories like this are exactly why sticking to well-established, independently audited providers with a public security track record matters more than finding the cheapest or most obscure option available. Established providers with active bug bounty programs and a history of public, named security audits have far more scrutiny on their build and distribution pipelines than a smaller regional tool most Western security researchers have never examined. That doesn’t make smaller tools inherently unsafe, but it does mean fewer independent eyes are watching for exactly this kind of supply chain compromise.

Our verdict

A trojanized installer running undetected for a year, on a tool people specifically downloaded to protect themselves, is a serious failure that took too long to catch. If you use regional VPN or proxy tools outside the mainstream, audited providers, update immediately when a compromise is disclosed and don't assume an uninstall alone removes everything a modular backdoor may have deployed. For most users, sticking with an established, audited, actively bug-bountied provider remains the lower-risk choice.

Keep reading: Is This VPN Safe to Use? A Checklist for Unknown Providers and Why You Should Not Buy a VPN You Haven’t Vetted.