Chinese hackers are using this open-source VPN to mask spying activities

Hand with mobile phone and VPN application, Chinese flag on laptop screen on the background
(Image credit: Getty Images)

Chinese hackers are relying on legitimate VPN services to mask illegal activities, and for the first time, a diplomatic organization in the European Union is among their targets.

These findings come from the latest ESET report on APT (Advanced Persistent Threat) groups' activities between April and September 2024.

All the best VPN apps encrypt internet connections to prevent third-party access while spoofing users' real IP addresses for maximum online anonymity. But what if those who use these services are professional government-backed hackers?

SoftEther VPN: hackers' tool of choice

"One trend that we noticed among several China-aligned threat actors is the use of SoftEther VPN instead of their usual implants or backdoors," Mathieu Tartare, senior malware researcher at ESET, told Cyberscoop.

SoftEther VPN is an open-source virtual private network (VPN) software that can use HTTPS connections to establish a VPN tunnel. This allows its users to bypass a company's firewall, for instance, while blending into legitimate traffic.

Experts observed the Webworm APT group, a cyberespionage group linked to China, switching from full-featured backdoors (such as the Trochilus RAT) to the SoftEther VPN Bridge on compromised machines of several governmental organizations in the EU.

"Such a VPN bridge allows the attacker to establish direct communication between the attacker-controlled infrastructure and the victim’s local network, bypassing port filtering and accessing resources that might be blocked on the external router or firewall of the targeted organization," noted researchers.

Webworm wasn't the only group regularly deploying SoftEther VPN, either. GALLIUM, Flax Typhoon, and MirrorFace all have been using the VPN service during the research period with the latter making regular use of it since the end of 2023.

For the very first time, the MirrorFace group also expanded its target list outside Japan, including an EU diplomatic organization alongside its usual targets.

Researchers did not name the compromised organization. Yet, the attack still appears to be linked with Japanese affairs as hackers sent the victim a phishing email about the 2025 World EXPO exhibition, which is set to be held in Osaka.

Talking to Cyberscoop, Tartare said organizations should consider any SoftEther VPN executables deployed on the network as suspicious and block them if they aren't needed. You should be especially wary of those SoftEther VPN executables that do not have the right filename, he added.

For more tips and tools on how to secure your organizations, I recommend checking our dedicated pages of the best business VPNs and endpoint protection software currently on the market.

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
China
Chinese hackers develop effective new hacking technique to go after business networks
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
malware
Google warns of legit VPN apps being used to infect devices with malware
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
China flag with the words "Best VPN for China" overlayed
The best VPN for China 2025
Latest in VPN Privacy & Security
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)