SoftEther VPN is an open-source VPN software suite that threat actors repeatedly abuse as a legitimate remote-access tool for stealthy communications, persistence, and bypassing network restrictions. The provided reporting describes use of SoftEther VPN clients and SoftEther VPN Bridge by multiple China-linked espionage clusters, including CL-STA-0048, UNC2814, UAT-7237, Flax Typhoon, and GALLIUM/Red Dev 4. Observed tradecraft includes delivery of SoftEther VPN clients configured to connect to attacker-controlled infrastructure; deployment of SoftEther VPN Bridge to create encrypted outbound connections; and installation of renamed binaries for defense evasion and persistence, including conhost.exe in C:\Windows\SysWOW64, oracll.exe, and bridge.exe in System32. In one reported case, attackers created a service named SysBridge to auto-start the renamed SoftEther binary at reboot, and the process established outbound HTTPS connections to an attacker-controlled IP on port 443 to create a covert VPN channel. UAT-7237 reportedly used SoftEther VPN alongside RDP for persistent access to compromised Taiwanese web-hosting infrastructure, with observed SoftEther-related infrastructure spanning roughly September 2022 through December 2024 and Simplified Chinese configured as the preferred display language. Flax Typhoon used a renamed SoftEther executable to maintain covert access after compromising an ArcGIS environment, while Red Dev 4/GALLIUM used SoftEther VPN clients to maintain footholds in telecommunications victims. Across the cited incidents, SoftEther VPN is associated with long-term persistence, covert remote administration, and lateral-enablement in victim environments, especially in telecommunications, government, web infrastructure, and other high-value networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We will discuss some of the recent techniques we’ve seen Red Dev 4 use to maintain footholds within victim environments, such as the delivery of SoftEther VPN clients configured to connect to threat actor-owned infrastructure.
We will discuss some of the recent techniques we’ve seen Red Dev 4 use to maintain footholds within victim environments, such as the delivery of SoftEther VPN clients configured to connect to threat actor-owned infrastructure.
"We also identified a SoftEther VPN binary placed at C:\Windows\SysWOW64\conhost.exe..."
"...and deployed SoftEther VPN Bridge to create an encrypted outbound connection."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor installs the SoftEther VPN on compromised public-facing servers and uses certutil commands to download and install the SoftEther VPN server.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
VShell is a backdoor malware developed in the Go programming language... supports protocols such as TCP, HTTP, and UDP for communication with the C&C server
establish persistent tunneling infrastructure using SoftEther VPN, Yuze, and VNT, all disguised as VMware executables or XDR agents
The compressed file containing XMRig was downloaded through the following command: > Bitsadmin /transfer
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate VPN software abused post-compromise to establish an encrypted outbound connection (tunneling) from victim environments.
Legitimate VPN software abused/installed by attackers for remote access and persistence (noted masquerading as conhost.exe).
Legitimate VPN software deployed/abused to provide remote access and persistence (noted in an intrusion linked by vendors to Flax Typhoon).
SoftEther VPN, in this context, is a legitimate VPN software repurposed by attackers as a backdoor. By renaming and installing it as 'bridge.exe', attackers establish a covert VPN tunnel to maintain persistent, stealthy access to the compromised network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.