Back to Feed
Supply ChainJul 19, 2026

Hackers abuse ViPNet software to target Russian govt agencies

HelloNet campaign abuses ViPNet update mechanism to target Russian government and critical infrastructure.

Summary

An advanced threat actor dubbed HelloNet has been exploiting the ViPNet private networking product's update mechanism since at least May 2026 to target Russian government agencies and critical infrastructure sectors. The campaign deploys HelloInjector (wtsapi32.dll) via DLL sideloading to establish persistence and execute additional malware modules including HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor. Kaspersky attributes the campaign with low confidence to an unidentified Chinese-speaking APT group but notes the possibility of a false flag operation.

Full text

Hackers abuse ViPNet software to target Russian govt agencies By Bill Toulas July 19, 2026 10:23 AM 0 An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware. According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors. ViPNet update abuse ViPNet is a family of Russian information-security products developed by InfoTeCS, providing VPN, endpoint, and network access protection, firewall, certificate management, centralized administration, and secure messaging and file transfer. The tool is commonly used in Russia, where it is certified by the authorities for use in government and other regulated environments. Due to its market reach in Russia, especially among high-value organizations, it has been targeted often by hackers. In April, 2025, Kaspersky reported that threat actors impersonated a ViPNet update in attacks. In the latest campaign, attackers placed a malicious file (wtsapi32.dll, dubbed HelloInjector) inside the local ViPNet Update System directory to be sideloaded at system startup via the legitimate itcsrvup64.exe. This DLL is the first-stage loader that injects into the svchost.exe process, granting next-stage payloads elevated privileges on Windows and persistence across reboots. Kaspersky does not describe exactly how the attackers gained initial access to perform this file change, nor do they claim that ViPNet’s update infrastructure itself was compromised. Malware toolset HelloInjector runs its embedded payload, which Kaspersky named HelloProxy, in memory and contacts the command-and-control (C2) server to receive additional modules. One of these modules is HelloExecutor, a backdoor that can execute commands and conduct network reconnaissance on the host. A second one is HelloCleaner, a tool that removes ViPNet log data to hide the malicious activity. Another implant called HelloBackdoor is Rust-based and supports uploading and downloading files, as well as command execution. Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group. However, the researchers stressed that the evidence is weak, relying primarily on an unused string referencing the Chinese website sina.com and a malware download mirror hosted by the University of Science and Technology of China. As a result, they assign the attribution low confidence and do not rule out the possibility of a false flag operation. The cybersecurity firm recommends thorough monitoring of systems running ViPNet software, particularly traffic passing through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor). Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: U.S. offers $10 million for hackers targeting WhatsApp, Signal usersRussian hackers trojanize WebEx, Zoom apps to push Starland malwareGoogle Gemini CLI abused as a hacking agent, malware botnet operatorUS charges alleged operators of Russian bulletproof hosting serviceEU sanctions Russian GRU military hackers over cyberattacks

Indicators of Compromise

  • malware — HelloInjector
  • malware — HelloProxy
  • malware — HelloExecutor
  • malware — HelloCleaner
  • malware — HelloBackdoor

Entities

ViPNet (product)InfoTeCS (vendor)Kaspersky (vendor)HelloNet (campaign)Chinese-speaking APT group (unidentified) (threat_actor)