A legitimate installer for QuickFox VPN was reportedly altered to deliver malware to unsuspecting Windows users. Fortinet researchers linked the tampering to suspected Chinese hackers, according to the available report details.
The modified program was designed to install the VPN while also secretly downloading a backdoor. That secondary payload could give attackers a foothold on affected computers beyond the VPN’s intended functionality.
The incident highlights the risks of downloading software that appears legitimate but has been changed before reaching users. Windows installations were the focus of the reported campaign, with the malicious modification embedded in the QuickFox distribution process.
Fortinet’s findings place the case among attacks that abuse trusted software to reach victims, although the available information does not establish the attackers’ identity conclusively.