securelist.com HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation
Article Content
- •HelloNet campaign exploits ViPNet software to target Russian government and sectors.
- •Malicious payloads include backdoors and tools for network reconnaissance and log deletion.
- •Kaspersky attributes the attack to a Chinese-speaking APT group with low confidence.
An advanced threat actor, identified as HelloNet, is exploiting the ViPNet software update mechanism to target Russian government agencies and other sectors. The campaign has been active since May 2026, deploying a malicious payload that acts as a proxy and loader for additional malware. Kaspersky researchers report that organizations in government, energy, transport, education, and logistics have been affected. The attackers sideloaded a malicious DLL (wtsapi32.dll) into the ViPNet Update System directory, allowing it to run at system startup. This DLL serves as a loader for further malicious payloads, including a backdoor named HelloExecutor and a tool named HelloCleaner that erases log data. Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking APT group but noted low confidence in this attribution. Security teams are advised to monitor traffic on specific ports associated with the malicious payloads. The ViPNet software is widely used in Russia and has been targeted previously by hackers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track HelloBackdoor and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…