A sophisticated threat actor has been exploiting the update mechanism of ViPNet software to target Russian government agencies and organizations across various sectors. The campaign, dubbed HelloNet, has been active since at least May 2026 and uses a malicious payload that acts as a proxy and loader for additional malware.
ViPNet is a suite of information-security products developed by InfoTeCS, which provides VPN, endpoint, and network access protection, among other features. It’s widely used in Russia, particularly among government agencies and regulated environments, due to its certification by Russian authorities. The software’s market reach in Russia has made it a prime target for hackers, with Kaspersky reporting similar attacks in April 2025 where threat actors impersonated a ViPNet update.
In the latest campaign, attackers have been placing a malicious file (wtsapi32.dll, dubbed HelloInjector) inside the local ViPNet Update System directory. This file is sideloaded at system startup via the legitimate itcsrvup64.exe and injects into the svchost.exe process, granting next-stage payloads elevated privileges on Windows and persistence across reboots.
The malicious payload, which Kaspersky has named HelloProxy, runs in memory and contacts a command-and-control (C2) server to receive additional modules. These modules include a backdoor called HelloExecutor, which can execute commands and conduct network reconnaissance on the host, as well as tools like HelloCleaner, which removes ViPNet log data to hide malicious activity.
Kaspersky has attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group, but notes that the evidence is weak and relies primarily on indirect indicators. As a result, they assign the attribution low confidence and do not rule out the possibility of a false flag operation.
Given the sophistication of this attack, it’s essential for security teams to take proactive measures to protect their systems running ViPNet software. Kaspersky recommends thorough monitoring of traffic passing through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor). It’s also crucial to regularly test system defenses against potential threats.
In today’s threat landscape, security teams often struggle to detect attacks before they cause damage. According to recent studies, security logs reveal that up to 54% of successful attacks go undetected until it’s too late. Regular breach and attack simulation tests can help fortify defenses and prevent such incidents from occurring in the first place.
Source: Bleeping Computer — 2026-07-19