Automatically translated.View original post

Hackers found. Secretly embedded malware on a Chinese VPN installer.

Hackers found. Secretly embedded malware onto a Chinese VPN installer. QuickFox aimed at tackling Windows users.

According to a report by the website, Techradar has mentioned the detection of a malware-type open back door or backdoor campaign on software for virtual networking or VPN (Virtual Private Network) from China, QuickFox, whose internal malware code is fielded within the file's HTML file, installed the software to extract the real malware code (Payload) in JavaScript from a domain named to emulate the infrastructure of the VPN system in the camp for settlement, according to the Fortiguard research team of network expert company Fortinet. The campaign is not new, but it has been ongoing since August 2025, and QuickFox has now modified the malware code through updated version 3.59.6.

A notable point is that the malware is not intended to tackle all VPN users, but is specifically focused on IT employees in positions such as Developer, IT Administrator, and Cryptocurrency users. The feature checks for relevant software on board, such as Visual Studio Code, Telegram, or Crypto Wallet. If detected, the malware will use Windows tools to install FDMTP Implant. Instantly shoot the malware code on the system. The malware stores data on the victim's system, such as the IP number, MAC Address, and Username, etc. And since the FDMTP malware is modular, the malware can download other features later.

But on the contrary, if video game software such as Steam is detected, the malware will immediately stop spreading in the system because the gaming computer is not a valuable enough victim to spread the malware.

# Trending # lemon 8 diary # vpn China # vpn # freedomhack

9/7 Edited to

... Read moreจากประสบการณ์การใช้งาน VPN เพื่อเพิ่มความปลอดภัยในการเชื่อมต่ออินเทอร์เน็ต ฉันได้เรียนรู้ว่าแม้ซอฟต์แวร์ VPN จะช่วยปกป้องข้อมูล แต่ก็ยังมีช่องโหว่ที่แฮกเกอร์สามารถใช้ประโยชน์ได้เหมือนกรณีของ QuickFox VPN จากจีนที่ถูกตรวจพบว่ามีมัลแวร์แอบฝังมากับไฟล์ติดตั้ง มัลแวร์ที่ซ่อนอยู่ในไฟล์ HTML ของตัวติดตั้งนี้ไม่เหมือนมัลแวร์ทั่วไป เพราะมันถูกออกแบบมาเพื่อเปิดประตูหลัง (Backdoor) โดยใช้ JavaScript และดาวน์โหลดโค้ดเพิ่มเติมเข้าสู่ระบบอย่างเนียน ๆ ซึ่งแสดงให้เห็นถึงความซับซ้อนและความเฉพาะเจาะจงในการมุ่งโจมตีผู้ใช้งาน บริการนี้เจาะจงกลุ่มเป้าหมายที่เกี่ยวข้องกับงานไอที เช่น นักพัฒนาซอฟต์แวร์และผู้ดูแลระบบ รวมถึงกลุ่มผู้ใช้งานเหรียญคริปโตเคอร์เรนซีด้วย สิ่งที่ฉันสนใจมากคือมัลแวร์นี้มีฟีเจอร์ตรวจสอบซอฟต์แวร์ที่ติดตั้งบนเครื่องก่อนจะลงมือโจมตี เช่น ถ้ามีโปรแกรม Visual Studio Code หรือ Telegram อยู่ จะถูกมองว่าเป็นเป้าหมายสำคัญ แต่ถ้าพบโปรแกรมเกมอย่าง Steam กลับไม่ถูกโจมตี ทั้งนี้เพราะมัลแวร์ประเมินว่าเครื่องที่ใช้เล่นเกมไม่น่าสนใจเท่ากลุ่มไอทีและคริปโต นี่เป็นการสอนใจให้กับผู้ใช้งาน VPN ว่าควรจะเลือกใช้ซอฟต์แวร์ที่มีความน่าเชื่อถือและอัปเดตเวอร์ชันล่าสุดเสมอ นอกจากนี้ยังควรระวังแหล่งดาวน์โหลดโปรแกรม VPN เพื่อไม่ตกเป็นเหยื่อของแฮกเกอร์ที่ใช้วิธีการฝังมัลแวร์ซับซ้อนเช่นนี้ จากกรณีนี้ ทำให้เราต้องตระหนักถึงความเสี่ยงด้านไซเบอร์ที่อาจเกิดขึ้นกับโปรแกรมที่ดูเหมือนปลอดภัยและได้รับความนิยม การใช้งาน VPN ควรมาพร้อมกับความระมัดระวังเป็นพิเศษ โดยเฉพาะหากใช้งานในกลุ่มที่เกี่ยวข้องกับข้อมูลสำคัญหรือธุรกรรมคริปโตเคอร์เรนซี สุดท้ายนี้แนะนำให้ผู้ที่ใช้งาน QuickFox VPN เร่งตรวจสอบและอัปเดตซอฟต์แวร์เป็นเวอร์ชัน 3.59.6 หรือใหม่กว่า เพื่อป้องกันการถูกโจมตีจากมัลแวร์แฝง และติดตามข่าวสารด้านความปลอดภัยไซเบอร์อย่างสม่ำเสมอเพื่อรับมือกับภัยคุกคามที่เปลี่ยนแปลงอย่างรวดเร็ว