A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.
The HelloNet campaign utilizes the ViPNet private networking product suite, specifically targeting Russian organizations including government agencies. Kaspersky researchers reported that this campaign has been active since at least May, employing a malicious payload that facilitates further malware deployment.
ViPNet, developed by InfoTeCS, provides a range of security solutions including VPN and network access protection. The software is widely used in Russia and certified for government use, making it a recurring target for attackers due to its extensive reach in critical sectors.
The attackers introduced a malicious DLL file, wtsapi32.dll, known as HelloInjector, into ViPNet's Update System directory. This file is designed to execute at system startup, allowing the malware to gain elevated privileges on Windows systems and maintain persistence.
HelloInjector loads additional malware modules such as HelloProxy, which communicates with a command-and-control server. Other modules include HelloExecutor, a backdoor for executing commands, and HelloCleaner, which erases log data to conceal the attacker's actions.
Kaspersky has tentatively attributed the HelloNet campaign to an unidentified Chinese-speaking APT group based on weak evidence, including references to Chinese websites. The specifics of the initial access method remain undetermined, leaving potential vulnerabilities in ViPNet's update process under scrutiny.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.