SoftEther VPN is legitimate open-source VPN software that threat actors abuse for persistent remote access, encrypted communications, and covert connectivity into compromised networks. Its client, server, and bridge components can connect victim systems to attacker-controlled VPN infrastructure or extend internal networks to remote locations. It is not inherently malware.
In malicious deployments, operators rename SoftEther binaries to resemble trusted operating-system or application components and configure services or startup execution to maintain access after reboot. Outbound encrypted connections, including HTTPS-based tunnels, help bypass network restrictions and conceal remote-access traffic. Some deployments use cascading VPN connections to upstream servers. SoftEther provides network access rather than credential-stealing or arbitrary-command-execution functionality; attackers use separate tools and protocols, including RDP, for subsequent operations.
Documented abuse includes activity tracked as Flax Typhoon, UAT-7237, GALLIUM/Red Dev 4, Soft Cell, UNC2814, and Larva-26010. Deployments have occurred in telecommunications, government, web-hosting, and critical-infrastructure environments, including Taiwanese organizations and Korean web and database servers. Attackers typically install the software after obtaining an initial foothold, using compromised servers, web shells, or command-line download utilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Actors install SoftEther VPN clients disguised as conhost.exe or dllhost.exe to maintain stealthy, startup-persistent remote access.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN.
We will discuss some of the recent techniques we’ve seen Red Dev 4 use to maintain footholds within victim environments, such as the delivery of SoftEther VPN clients configured to connect to threat actor-owned infrastructure.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
Similarly, while both Flax Typhoon and Storm-0558 have used SoftEther VPN software for communication with victim devices, Storm-0558’s activities have targeted a wider variety of organizations than Flax Typhoon’s.
The threat actors... installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers.
establish persistent tunneling infrastructure using SoftEther VPN, Yuze, and VNT, all disguised as VMware executables or XDR agents
The campaign installed backdoors including Cobalt Strike, RESHELL, and XDealer on compromised servers.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate VPN software explicitly abused in the intrusion for persistent remote access. Clients are disguised using executable names conhost.exe or dllhost.exe; the content does not describe a distinct malware family or modification of the software.
Legitimate VPN software explicitly abused by attackers, who installed it on victim devices to retain access. The reference describes malicious persistence use, not a trojanized version or an inherently malicious malware family.
An open-source VPN tool abused by the threat actor to turn compromised web and MS-SQL servers into VPN servers, likely for relay, persistence, and concealed command-and-control via cascade connections.
Legitimate VPN software abused post-compromise to establish an encrypted outbound connection (tunneling) from victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.