Home / Technology / China VPN Hacked: Malware Sneaks Through
China VPN Hacked: Malware Sneaks Through
6 Aug
Summary
- QuickFox VPN tampered with to deliver malware to users.
- Suspected Chinese state-sponsored group Mustang Panda behind attack.
- Malware targets Windows, despite presence in Mac installer.

A QuickFox VPN program originating from China was covertly modified to distribute malware to its users. Cybersecurity vendor Fortinet identified malicious JavaScript within the legitimate software, suspecting the Chinese hacking group Mustang Panda. This malware is designed to identify "valid targets" on Windows computers before installing a backdoor for espionage.
While the exact method of compromise remains unknown, attackers inserted malicious JavaScript. This code fetches and executes files from a hacker-controlled domain. Affected QuickFox versions range from 3.51.0 to 3.55.5, observed starting in August 2026. Although the malicious JavaScript was present in the Mac installer, the observed infection behavior was specific to Windows users.
QuickFox has responded by removing the trojanized components and initiating an internal investigation. The latest version, 3.59.6, has eliminated the malicious code. However, Fortinet warns that the malware infrastructure remains active, with communication links to domains active since at least June 30, 2026, indicating a persistent campaign.