logo

Abusing Windows Built-in VPN Providers

ID: d22a8175-2874-5a54-a953-00aa43b0d191

STIX ID: report--d22a8175-2874-5a54-a953-00aa43b0d191

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-12-16

Date Updated: 2026-05-01

...
...

Executive summary: The report demonstrates that Windows' built-in VPN providers can be abused by non‑privileged users to modify the system routing table (via phonebook files, PowerShell/WMI cmdlets, RasMan RPC, etc.) and redirect or intercept network traffic through an attacker-controlled VPN (SoftEther example). It covers methods to push or locally add routes, tunnel all traffic, auto‑connect via application triggers, attack scenarios (dropping traffic to blind EDR/logging or redirecting to a MitM proxy), and detection/prevention recommendations (restrict RasMan/phonebook writes, monitor RasClient events).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.