Multiple threat actors have used SoftEther VPN to turn compromised servers into covert relay infrastructure and maintain persistent access after initial intrusion. AhnLab reported that the Larva-26010 group targeted web and MS-SQL servers in Korea, installing SoftEther components under ProgramData, disguising binaries as legitimate files such as vmtoolsd.Exe, and configuring cascade connections to upstream VPN servers to mask command-and-control paths. The intrusions also involved discovery commands, deployment of CLR SqlShell, registry changes including UseLogonCredential, web shell installation, and in one case creation of a local administrator-like account.
Other reporting shows the same tunneling approach appearing in broader espionage operations. Mandiant found that UNC3500 exploited Log4Shell (CVE-2021-44228) on public-facing MobileIron servers and established persistence with a SoftEther/PacketiX VPN Bridge, while Kaspersky said ToddyCat used SoftEther VPN Server alongside reverse SSH tunnels, ngrok, FRP, and a custom proxy to preserve access and support large-scale data theft from government and defense-related targets in the Asia-Pacific region. Across the cases, SoftEther was used not as the initial exploit but as post-compromise infrastructure for stealthy remote access, lateral movement support, and exfiltration-enabling traffic tunnels.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC observed related Larva-26010 attacks between April and August 2026 in which the actor first abused web servers to run discovery and SoftEther installation commands, then later targeted MS-SQL servers to deploy CLR SqlShell. This marked a change from earlier cases that began with MS-SQL compromise.
AhnLab ASEC said Larva-26010 has targeted domestic web servers and MS-SQL servers in Korea since at least 2024, using compromised systems as VPN infrastructure. Earlier cases documented in 2024 involved poorly managed MS-SQL servers and SoftEther VPN installation.
In a separate intrusion during the same Log4Shell campaign, UNC961 exploited a VMware Horizon Server and deployed two previously unobserved backdoors, HOLEDOOR and DARKDOOR. The actor used them for reconnaissance and credential theft, including exporting registry hives and exfiltrating them with PSCP.
The day after initial access, UNC961 deployed the HOLEPUNCH tunneler to multiplex connections to command-and-control infrastructure. This followed Log4Shell exploitation and reconnaissance on the victim environment.
One day after the initial Apache announcement, UNC3500 targeted a North American educational institution, exploited Log4Shell on a MobileIron server, and established persistence by downloading and running SoftEther/PacketiX VPN Bridge components. The actor also cleared bash history after setup.
UNC961 exploited publicly accessible MobileIron servers with Log4Shell, using payloads that unset HISTFILE and launched reverse shells. The group then performed host-based reconnaissance on compromised systems.
After exploiting MobileIron, APT41 downloaded an ELF file named "kernel," which Mandiant assessed as a Linux variant of KEYPLUG, then renamed it to ".kernel" and executed it for persistence and command-and-control. The malware was configured to use microsoftfile[.]com for C2.
APT41 used Log4Shell against vulnerable MobileIron servers at at least four organizations, including a telecom company, a U.S. financial organization, and two U.S. state government agencies. The actor launched reverse shells and tested outbound connectivity from compromised servers.
In December 2021, multiple threat actors exploited CVE-2021-44228 against publicly accessible MobileIron servers to gain initial access, validate connectivity, and deploy reverse shells and follow-on tooling. Mandiant's survey ties this activity to APT41, UNC961, UNC3500, and UNC3535.
Kaspersky reported ToddyCat using multiple redundant tunnels including OpenSSH reverse tunnels, SoftEther VPN Server, ngrok, Krong, and FRP after obtaining high-privileged credentials in government and defense environments in the Asia-Pacific region. The group also used cuthead, WAExp, and TomBerBil to automate document, WhatsApp, cookie, and password theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcesecurelist.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.