SoftEther VPN is a legitimate open-source VPN platform that is frequently repurposed by threat actors as a covert remote-access and persistence mechanism after compromise. In intrusion activity attributed to multiple China-linked espionage clusters and other operators, attackers have installed renamed SoftEther components on compromised systems to create encrypted outbound tunnels, bypass network restrictions, and maintain durable access while blending with legitimate administrative traffic. Observed use includes deployment of the VPN client, VPN server, and VPN Bridge variants on compromised infrastructure.
Abuse of SoftEther VPN has been documented on Windows and Linux systems, including web servers, Microsoft SQL Server hosts, Exchange-adjacent infrastructure, ArcGIS servers, and telecom environments. Operators have used it to turn victim systems into relay or VPN infrastructure, establish covert channels to attacker-controlled systems, and support later access via RDP or other post-compromise tooling. In several cases, attackers renamed the binaries, installed them as services, stored supporting configuration and resource files separately, and configured cascade or bridge connections to upstream VPN nodes to obscure their real command-and-control architecture.
Threat actors associated with SoftEther VPN abuse in reported intrusions include Larva-26010, UAT-7237, Flax Typhoon, UNC2814, CL-STA-0048, and activity linked to GALLIUM/Red Dev 4 and Soft Cell. These campaigns have targeted telecommunications providers, government entities, web hosting and web infrastructure organizations, and other high-value networks, particularly in Asia. SoftEther VPN itself is not inherently malicious, but in these operations it functioned as a stealthy post-compromise access tool that enabled persistence, defense evasion, and continued operator access to victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
We will discuss some of the recent techniques we’ve seen Red Dev 4 use to maintain footholds within victim environments, such as the delivery of SoftEther VPN clients configured to connect to threat actor-owned infrastructure.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
Similarly, while both Flax Typhoon and Storm-0558 have used SoftEther VPN software for communication with victim devices, Storm-0558’s activities have targeted a wider variety of organizations than Flax Typhoon’s.
The threat actors... installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers.
establish persistent tunneling infrastructure using SoftEther VPN, Yuze, and VNT, all disguised as VMware executables or XDR agents
The campaign installed backdoors including Cobalt Strike, RESHELL, and XDealer on compromised servers.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source VPN tool abused by the threat actor to turn compromised web and MS-SQL servers into VPN servers, likely for relay, persistence, and concealed command-and-control via cascade connections.
Legitimate VPN software abused post-compromise to establish an encrypted outbound connection (tunneling) from victim environments.
Legitimate VPN software abused/installed by attackers for remote access and persistence (noted masquerading as conhost.exe).
Legitimate VPN software deployed/abused to provide remote access and persistence (noted in an intrusion linked by vendors to Flax Typhoon).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.