PCMag·2 min read·medium

Suspected Chinese Hackers Compromised This VPN to Deliver Malware

M
Michael Kan
Suspected Chinese Hackers Compromised This VPN to Deliver Malware
AI Summary

Cybersecurity researchers at Fortinet have discovered that the QuickFox VPN for Windows was compromised to deliver malware. The attack is attributed to a state-sponsored Chinese hacking group known as Mustang Panda.

<p>A <a href="https://www.pcmag.com/picks/the-best-vpn-services" target="_self">VPN</a> program from China was secretly tampered with to deliver <a href="https://www.pcmag.com/picks/the-best-malware-removal-and-protection-software" target="_self">malware</a> to unsuspecting users, according to researchers at cybersecurity vendor Fortinet. </p><p>The attack targeted Windows installations for QuickFox VPN. Fortinet suspects a state-sponsored Chinese hacking group called Mustang Panda (aka Twill Typhoon) is behind it.</p><p>Researchers <a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" title="(Opens in a new tab)">uncovered</a> the threat in malicious JavaScript within an "embedded Electron renderer HTML file bundled" into the legitimate QuickFox app. Once it executes, the JavaScript fingerprints the victim's computer to determine if it's a "valid target" before downloading and installing a backdoor capable of spying on a PC and downloading additional files. </p><div class="mb-0 rounded-md bg-gray-100 p-3 md:p-5" id="related-video">

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyworld

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in