Skip to content
HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation

HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation

First seen 19 Jul 2026, 16:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 20, 2026 at 15:03 UTC
  • HelloNet campaign exploits ViPNet software to target Russian government and sectors.
  • Malicious payloads include backdoors and tools for network reconnaissance and log deletion.
  • Kaspersky attributes the attack to a Chinese-speaking APT group with low confidence.

An advanced threat actor, identified as HelloNet, is exploiting the ViPNet software update mechanism to target Russian government agencies and other sectors. The campaign has been active since May 2026, deploying a malicious payload that acts as a proxy and loader for additional malware. Kaspersky researchers report that organizations in government, energy, transport, education, and logistics have been affected. The attackers sideloaded a malicious DLL (wtsapi32.dll) into the ViPNet Update System directory, allowing it to run at system startup. This DLL serves as a loader for further malicious payloads, including a backdoor named HelloExecutor and a tool named HelloCleaner that erases log data. Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking APT group but noted low confidence in this attribution. Security teams are advised to monitor traffic on specific ports associated with the malicious payloads. The ViPNet software is widely used in Russia and has been targeted previously by hackers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 64d ago How this analysis works

Timeline

2025-04-01
Previous ViPNet attacks reported
Kaspersky reported earlier attacks where threat actors impersonated ViPNet updates, indicating ongoing targeting of the software.
BleepingComputer
2026-05-01
HelloNet campaign begins
The HelloNet campaign commenced, exploiting the ViPNet update mechanism to deploy malicious payloads across various sectors in Russia.
BleepingComputer
2026-07-19
Kaspersky publishes findings
Kaspersky released details on the HelloNet campaign, revealing its methods and impact on Russian organizations.
securelist.com

More articles in this cluster (4)

Following this threat?

Track HelloBackdoor and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed