SoftEther VPN is a legitimate VPN/proxy software tool that appears in intrusion activity as attacker infrastructure rather than as custom malware. In the provided reporting, it is used by threat actors including Flax Typhoon and has also been linked to Earth Krahang and ToddyCat. Microsoft reported Flax Typhoon using the SoftEther VPN client after exploiting known vulnerabilities in public-facing servers and deploying web shells; the group used it alongside tools such as China Chopper, Metasploit, Juicy Potato, and Mimikatz to maintain access, route activity through compromised environments, and support persistent access and reconnaissance. The content associates Flax Typhoon’s operations primarily with espionage targeting Taiwanese government, education, critical manufacturing, and IT organizations. Separate infrastructure analysis found SoftEther proxies to be long-lived, with a median observed duration of 59 days and some instances remaining online for the full 90-day observation window, indicating its role as persistent operational infrastructure for APT activity. No malware-specific infection vector or standalone IOC for SoftEther itself is provided in the content beyond its use as VPN/proxy infrastructure and client software in post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
« LIGHTPAINT ... installant un VPN légitime (SoftEther) avec persistence automatisée »
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SoftEther is an open-source VPN and proxy tool used by attackers to create covert channels and maintain persistence in compromised environments.
A VPN client used by Flax Typhoon to establish persistent access and connect compromised systems to actor-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.