securelist.com
HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
An advanced threat actor, identified as HelloNet, is exploiting the ViPNet software update mechanism to target Russian government agencies and other sectors. The campaign has been active since May 2026, deploying a malicious payload that acts as a proxy and loader for additional malware. Kaspersky researchers report that organizations in government, energy, transport, education, and logistics have been affected. The attackers sideloaded a malicious DLL (wtsapi32.dll) into the ViPNet Update System directory, allowing it to run at system startup. This DLL serves as a loader for further malicious payloads, including a backdoor named HelloExecutor and a tool named HelloCleaner that erases log data. Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking APT group but noted low confidence in this attribution. Security teams are advised to monitor traffic on specific ports associated with the malicious payloads. The ViPNet software is widely used in Russia and has been targeted previously by hackers.
Key Points: • HelloNet campaign exploits ViPNet software to target Russian government and sectors. • Malicious payloads include backdoors and tools for network reconnaissance and log deletion. • Kaspersky attributes the attack to a Chinese-speaking APT group with low confidence.