Back to advisories

Hackers abuse ViPNet software to target Russian govt agencies

Advanced threat actor HelloNet is actively exploiting ViPNet's update mechanism to compromise Russian government and critical infrastructure targets since May 2026. The attack chain uses DLL sideloading to deploy persistent backdoors and additional malware modules. This represents a supply chain compromise affecting a trusted VPN/networking product used by sensitive organizations.

CRITICALAdvisoryJul 21, 2026
Action required
Immediately hunt for HelloInjector (wtsapi32.dll) DLL sideloading artifacts and HelloNet malware modules (HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) in your environment. Block known C2 infrastructure and audit ViPNet update integrity on all endpoints.
Affected products
ViPNetInfoTeCSKaspersky