In short: On October 8, 2026, the FBI, CISA, NSA, and agencies from the UK, Australia, Canada, Japan, New Zealand, and Spain issued a joint advisory, AA26-281A: Chinese government-linked hacking groups — enabled by infrastructure from Integrity Technology Group — have been mass-installing the legitimate SoftEther VPN client on compromised machines, renaming it conhost.exe or dllhost.exe so it looks like an ordinary Windows system process. Through that hidden VPN tunnel, attackers maintain long-term access to government, healthcare, IT, and education networks across the US, Southeast Asia, and Africa, and exfiltrate data. None of it relied on zero-day flaws — just old, well-known, long-patched holes from 2014–2023 that organizations simply never got around to closing.
What the advisory found
SoftEther is only part of the toolkit. According to the joint report, the attackers first scan the internet with NMAP, Fscan, and a custom tool called MicroScan — a Python utility packed with more than 1,300 ready-made scripts for finding vulnerable servers. Next comes EBurst, a password-spraying tool aimed at Microsoft Exchange servers through Outlook Web Access and the Exchange Control Panel. For quiet exfiltration of mail and documents, they use office-cli, which automates Microsoft 365 email access through what look like legitimate methods — making detection considerably harder. We covered the broader pattern of disguising malicious activity as ordinary VPN traffic in our piece on malicious VPN apps.
Why disguise a VPN as conhost.exe
SoftEther is a real, legitimate, free open-source VPN product used by administrators worldwide — which is exactly why antivirus and endpoint tools are less likely to flag it: technically, it isn't malware. The attackers install the SoftEther client on a compromised machine, configure it to reconnect automatically on startup, and rename the executable to a Windows system process — conhost.exe or dllhost.exe. The connection reaches out to a command-and-control (C2) server using a pre-registered domain or a raw IP address. The result isn't a one-time break-in but a persistent, hard-to-spot tunnel that can be used for years to pull out files and correspondence.
Who was targeted
In the US, the affected sectors include government services, critical manufacturing, healthcare, and IT. Outside the US, victims include law enforcement, educational, and religious organizations across Southeast Asia, Africa, and North America. The activity overlaps with clusters already tracked under the names Flax Typhoon, Ethereal Panda, and Red Juliett. The advisory specifically notes that attackers did not use a single zero-day — only eight long-known, already-patched CVEs (ranging from a 2014 Bash flaw to a 2023 Strapi flaw, affecting products from Apache, GitLab, Pulse Secure, and others) that organizations failed to update in time.
What this means for everyday users
This isn't a story about an attack on individual consumers, but it's a useful lesson about what a VPN actually is. A legitimate VPN client isn't inherently "good" or "bad" — what matters is who installed it, with what settings, and which server it connects to. The same logic is exactly why fake or "free" VPN apps from unverified sources are risky on an ordinary phone or laptop: they look like they're doing the same job as a real VPN, but the other end of the tunnel is an attacker's server, not the provider you actually trust. The difference isn't the technology — it's who controls the other end.
How to protect yourself
- Only install a VPN from an official app store or the developer's official site — our guide on downloading a VPN safely walks through exactly how to verify that.
- Keep your OS and server software updated — most of the attacks described in the advisory worked precisely because old vulnerabilities were never patched.
- For organizations: disable unused services and ports, enforce multifactor authentication everywhere, segment your network, and keep offline backups of critical data — these are AA26-281A's direct recommendations.
- If you administer systems, check
conhost.exeanddllhost.exeprocesses for unusual network behavior — those are exactly the names the advisory ties to disguised SoftEther activity.
A VPN itself isn't the threat here — it's a tool that, like any networking software, can be used for harm or for protection. For a VPN to actually work in your favor, the connection needs to go only to a provider you trust, with a clear logging policy: LiMP VPN runs on a verified no-logs policy, with plans from 69 ₽/month — details on the pricing page.
Sources
- CISA — joint advisory AA26-281A, "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data" (October 8, 2026)
- Pravda.ru — "Chinese hackers breached networks through old vulnerabilities: the FBI exposed the data-theft scheme" (October 9, 2026)
