Hackers abuse ViPNet software to target Russian govt agencies

A sophisticated threat actor has been exploiting a vulnerability in the update mechanism of ViPNet software to target government agencies and other organizations in Russia. Dubbed HelloNet, this campaign has been active since at least May and has already had a significant impact on various sectors, including government, energy, transport, education, and logistics.

ViPNet is a suite of private networking products developed by InfoTeCS that provides VPN, endpoint, and network access protection, among other features. It’s widely used in Russia, particularly in high-value organizations, which has made it an attractive target for hackers. In fact, Kaspersky researchers have previously reported on threat actors impersonating ViPNet updates in attacks as far back as April 2025.

The latest campaign involves attackers placing a malicious file called HelloInjector (wtsapi32.dll) inside the local ViPNet Update System directory. This DLL is then sideloaded at system startup via the legitimate itcsrvup64.exe, allowing it to inject into the svchost.exe process and grant next-stage payloads elevated privileges on Windows. The malware toolset used in HelloNet includes a backdoor (HelloExecutor) that can execute commands and conduct network reconnaissance, as well as tools to remove ViPNet log data and upload/download files.

Kaspersky researchers have attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group, but with low confidence due to weak evidence. The attribution is based on an unused string referencing a Chinese website and a malware download mirror hosted by a Chinese university. However, Kaspersky has not ruled out the possibility of a false flag operation.

The impact of HelloNet has been significant, with organizations across multiple sectors affected. Given the sophistication of the attack and the use of ViPNet software in high-value environments, it’s essential for security teams to be vigilant. Kaspersky recommends thorough monitoring of systems running ViPNet software, particularly traffic passing through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor).

In light of this attack, organizations should prioritize testing every layer of their security defenses before attackers do. This can be achieved through regular breach and attack simulation tests that validate the effectiveness of SIEM and EDR rules. By doing so, organizations can detect potential threats more effectively and reduce the risk of successful attacks slipping by detection. As always, a proactive approach to cybersecurity is key to staying ahead of sophisticated threat actors like those behind HelloNet.


Source: Bleeping Computer — 2026-07-19