Advanced Multi-Protocol VPN Client for Android (MASQUE, WireGuard, Gool, Zero Trust) powered by Aether Core and HEV SOCKS5 engine. High performance, DPI circumvention, and modern UI.
Kotlin
444
49 commits
updated Sep 14, 2026
Advanced, High-Performance Censorship Circumvention Client for Android & Windows
AetherST Tunnel is a production-grade VPN and Proxy client for Android and Windows, meticulously engineered to provide secure and stable connectivity in highly restricted network environments. By combining the power of the Aether Core with proven tunnel engines, AetherST offers a robust solution against Deep Packet Inspection (DPI) and protocol-based blocking across multiple platforms.
v1.7.1 (Latest Stable)v1.1.1 (First Public Release)AetherST Tunnel leverages cutting-edge protocols to ensure connectivity even in the most hostile network environments:
The flagship protocol for stealth. By tunneling traffic over QUIC (H3) or TLS (H2), it makes VPN traffic look like standard web browsing, making it highly resilient to Deep Packet Inspection (DPI).
A modern, high-performance VPN protocol that uses state-of-the-art cryptography. It is optimized for maximum speed and minimal battery drain on mobile devices.
A specialized nested WireGuard configuration. By wrapping one WireGuard tunnel inside another, it provides an additional layer of encryption and obfuscation, effectively bypassing many restrictive firewalls and improving stability.
Enterprise-grade security for individuals and organizations. It allows you to route your traffic through Cloudflare's global network using Gateway filtering and Service Tokens, ensuring zero-trust access control.
An optional second layer built on the open-source Psiphon tunnel core. It routes traffic via Psiphon to obtain a non-Iran exit IP and can chain over MASQUE, WireGuard, or Gool. Chain modes include Auto, Fallback, and Always, with a selectable egress region and local endpoints on 127.0.0.1:3080 (SOCKS) and 127.0.0.1:1820 (HTTP).
An optional second layer using the Tor implementation built into the Aether core β no separate Tor app or manual bridge setup required.
Chain provider selector: Settings β Connection lets you choose which second layer combines with Aether: Psiphon (default, backward compatible) or Tor. The Dashboard shows the settings card for the selected provider only.
Tor modes:
TOR): Aether connects first, then Tor rides inside it (you β WARP β Tor β internet). The Tor exit is exposed on the configured Tor port (default 127.0.0.1:3081). Works with any transport β MASQUE, WireGuard, Gool, and MASQUE-in-MASQUE.TOR_REVERSE): the tunnel is dialed through Tor, so WARP is reached from a Tor exit and the local network never sees WARP (you β Tor β WARP β internet). MASQUE over HTTP/2 only β WireGuard and Gool endpoints are UDP-only and are refused in this mode.TOR_ONLY): no Aether tunnel at all; the main proxy is plain Tor.Bridges & transports: where Tor is blocked, the core fetches its own bridges from BridgeDB for the country you appear to be in β no CAPTCHA, nothing to paste. Pluggable transports (obfs4, snowflake, webtunnel, meek) are discovered automatically; --tor-pt-dir remains available in settings as a manual override pointing at a folder with transport binaries. An optional bridge country, forced-bridges mode, and manual bridge lines are also exposed.
--mim)A MASQUE tunnel carried inside another MASQUE tunnel, changing the exit address the way Gool does but on the MASQUE carrier (HTTP/3 in HTTP/3, or HTTP/2 in HTTP/2 with --h2). The outer hop is found by scan and the inner one is picked automatically unless named explicitly, and it can carry Tor like any other transport.
The orchestration layer responsible for:
The native bridge between the system and Aether (Android Native):
The optional second-layer circumvention engine:
A unified UI layer sharing logic between Android and Desktop:
arm64-v8a is recommended)..msi or .exe installer../gradlew :app:assembleRelease./gradlew :composeApp:runThe project uses GitHub Actions for automated Multi-APK and Desktop releases.
Stay updated and get support through our official channels:
This project uses the following open-source resources:
Built with π by PowerSigma Team
Kotlin
88.2%
HTML
6.1%
C
5.2%
Advanced Multi-Protocol VPN Client for Android (MASQUE, WireGuard, Gool, Zero Trust) powered by Aether Core and HEV SOCKS5 engine. High performance, DPI circumvention, and modern UI.
Kotlin
444
49 commits
updated Sep 14, 2026
Advanced, High-Performance Censorship Circumvention Client for Android & Windows
AetherST Tunnel is a production-grade VPN and Proxy client for Android and Windows, meticulously engineered to provide secure and stable connectivity in highly restricted network environments. By combining the power of the Aether Core with proven tunnel engines, AetherST offers a robust solution against Deep Packet Inspection (DPI) and protocol-based blocking across multiple platforms.
v1.7.1 (Latest Stable)v1.1.1 (First Public Release)AetherST Tunnel leverages cutting-edge protocols to ensure connectivity even in the most hostile network environments:
The flagship protocol for stealth. By tunneling traffic over QUIC (H3) or TLS (H2), it makes VPN traffic look like standard web browsing, making it highly resilient to Deep Packet Inspection (DPI).
A modern, high-performance VPN protocol that uses state-of-the-art cryptography. It is optimized for maximum speed and minimal battery drain on mobile devices.
A specialized nested WireGuard configuration. By wrapping one WireGuard tunnel inside another, it provides an additional layer of encryption and obfuscation, effectively bypassing many restrictive firewalls and improving stability.
Enterprise-grade security for individuals and organizations. It allows you to route your traffic through Cloudflare's global network using Gateway filtering and Service Tokens, ensuring zero-trust access control.
An optional second layer built on the open-source Psiphon tunnel core. It routes traffic via Psiphon to obtain a non-Iran exit IP and can chain over MASQUE, WireGuard, or Gool. Chain modes include Auto, Fallback, and Always, with a selectable egress region and local endpoints on 127.0.0.1:3080 (SOCKS) and 127.0.0.1:1820 (HTTP).
An optional second layer using the Tor implementation built into the Aether core β no separate Tor app or manual bridge setup required.
Chain provider selector: Settings β Connection lets you choose which second layer combines with Aether: Psiphon (default, backward compatible) or Tor. The Dashboard shows the settings card for the selected provider only.
Tor modes:
TOR): Aether connects first, then Tor rides inside it (you β WARP β Tor β internet). The Tor exit is exposed on the configured Tor port (default 127.0.0.1:3081). Works with any transport β MASQUE, WireGuard, Gool, and MASQUE-in-MASQUE.TOR_REVERSE): the tunnel is dialed through Tor, so WARP is reached from a Tor exit and the local network never sees WARP (you β Tor β WARP β internet). MASQUE over HTTP/2 only β WireGuard and Gool endpoints are UDP-only and are refused in this mode.TOR_ONLY): no Aether tunnel at all; the main proxy is plain Tor.Bridges & transports: where Tor is blocked, the core fetches its own bridges from BridgeDB for the country you appear to be in β no CAPTCHA, nothing to paste. Pluggable transports (obfs4, snowflake, webtunnel, meek) are discovered automatically; --tor-pt-dir remains available in settings as a manual override pointing at a folder with transport binaries. An optional bridge country, forced-bridges mode, and manual bridge lines are also exposed.
--mim)A MASQUE tunnel carried inside another MASQUE tunnel, changing the exit address the way Gool does but on the MASQUE carrier (HTTP/3 in HTTP/3, or HTTP/2 in HTTP/2 with --h2). The outer hop is found by scan and the inner one is picked automatically unless named explicitly, and it can carry Tor like any other transport.
The orchestration layer responsible for:
The native bridge between the system and Aether (Android Native):
The optional second-layer circumvention engine:
A unified UI layer sharing logic between Android and Desktop:
arm64-v8a is recommended)..msi or .exe installer../gradlew :app:assembleRelease./gradlew :composeApp:runThe project uses GitHub Actions for automated Multi-APK and Desktop releases.
Stay updated and get support through our official channels:
This project uses the following open-source resources:
Built with π by PowerSigma Team
Kotlin
88.2%
HTML
6.1%
C
5.2%