← All stories
● Covered by 1 source · 1 reportHigh impact

Hackers Target Russian Government Agencies via ViPNet Software Abuse

Aggregated by BrevFeed security · updated 19h ago
🔖 Save

A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.

Key points

Attack Overview

The HelloNet campaign utilizes the ViPNet private networking product suite, specifically targeting Russian organizations including government agencies. Kaspersky researchers reported that this campaign has been active since at least May, employing a malicious payload that facilitates further malware deployment.

ViPNet Software Details

ViPNet, developed by InfoTeCS, provides a range of security solutions including VPN and network access protection. The software is widely used in Russia and certified for government use, making it a recurring target for attackers due to its extensive reach in critical sectors.

Malware Operation

The attackers introduced a malicious DLL file, wtsapi32.dll, known as HelloInjector, into ViPNet's Update System directory. This file is designed to execute at system startup, allowing the malware to gain elevated privileges on Windows systems and maintain persistence.

Malicious Payloads and Capabilities

HelloInjector loads additional malware modules such as HelloProxy, which communicates with a command-and-control server. Other modules include HelloExecutor, a backdoor for executing commands, and HelloCleaner, which erases log data to conceal the attacker's actions.

Attribution and Ongoing Investigation

Kaspersky has tentatively attributed the HelloNet campaign to an unidentified Chinese-speaking APT group based on weak evidence, including references to Chinese websites. The specifics of the initial access method remain undetermined, leaving potential vulnerabilities in ViPNet's update process under scrutiny.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

Reporting from

A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.