[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mru4s3ul":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"25eaa25c-e502-4a85-9f78-224c7b117cd6","Hackers abuse ViPNet software to target Russian govt agencies","hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mru4s3ul","Advanced threat actor HelloNet is actively exploiting ViPNet's update mechanism to compromise Russian government and critical infrastructure targets since May 2026. The attack chain uses DLL sideloading to deploy persistent backdoors and additional malware modules. This represents a supply chain compromise affecting a trusted VPN\u002Fnetworking product used by sensitive organizations.","critical","advisory",[],[13,14,15],"ViPNet","InfoTeCS","Kaspersky","Immediately hunt for HelloInjector (wtsapi32.dll) DLL sideloading artifacts and HelloNet malware modules (HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) in your environment. Block known C2 infrastructure and audit ViPNet update integrity on all endpoints.",[18],"868c9c3c-f462-49fe-9a95-ff27cc64ad02",null,[21],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-abuse-vipnet-software-to-target-russian-govt-agencies\u002F","active","2026-07-23T04:05:45.827+00:00","2026-07-21T04:05:48.569039+00:00","2026-07-21T04:07:06.418462+00:00",[27],{"id":18,"title":6,"url":21}]