Cybercriminals are exploiting the update mechanism of the ViPNet private networking product suite to target Russian organizations, including government entities.
Known as the HelloNet campaign, this threat has been active since at least May and deploys a malicious payload that serves as both a proxy and a loader for additional malware.
According to Kaspersky researchers, HelloNet has significantly impacted various sectors, including government, energy, transportation, education, and logistics.
Exploitation of ViPNet Updates
The ViPNet family includes a suite of Russian information security products developed by InfoTeCS, offering VPN, endpoint security, network access protection, firewalls, certificate management, central administration, secure messaging, and file transfer.
This software is widely used in Russia and is certified for government and regulated environments.
Hackers frequently target it due to its presence in high-value organizations in the Russian market. In April 2025, Kaspersky reported an attack where attackers impersonated a ViPNet Update to execute their infiltration.
In the latest campaign, attackers placed a malicious file (wtsapi32.dll, dubbed HelloInjector) inside the local ViPNet Update System directory, allowing it to be executed on system startup via the legitimate itcsrvup64.exe.
This DLL acts as a first-stage loader, injecting itself into the svchost.exe process, granting elevated privileges and persistence even after system reboots.
Kaspersky has not disclosed how the attackers gained initial access for this file modification, and it has not claimed that ViPNet’s update infrastructure was compromised.
Malware Toolkit
HelloInjector runs an embedded payload, known as HelloProxy, in memory, connecting to a Command and Control (C2) server to receive additional modules.
One of these modules, HelloExecutor, is a backdoor capable of executing commands and performing network reconnaissance.
The second module, HelloCleaner, erases ViPNet log data to obscure malicious activities.
Additionally, a Rust-based implant called HelloBackdoor supports file uploads and downloads, as well as command execution.
Kaspersky Lab tentatively attributes this campaign to an unidentified Chinese-speaking Advanced Persistent Threat (APT) group.
However, researchers emphasize that the evidence is tenuous, mainly based on unused strings linked to the Chinese website sina.com and a malware download mirror hosted by the University of Science and Technology of China.
Consequently, they assign a low confidence level to this attribution and do not rule out the potential for a false flag operation.
Cybersecurity experts advise closely monitoring systems utilizing ViPNet software, particularly traffic through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor).
Security teams document 54% of successful attacks but issue warnings on only 14%, while the rest remain undetected.
Picus’ whitepaper illustrates how to test your SIEM and EDR rules via breach and attack simulations to ensure threats don’t go unnoticed.
Source: www.bleepingcomputer.com




